Record summary

CVE-2024-44308 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2024-44308 in KEV.

Description

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 21, 2024 · CISA
VulnCheck KEV
Listed · Nov 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 23, 2024 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unknown

CVE ListBefore 18.1.1affected
Before 18.1affected
CVE ListBefore 17.7.2affected
Before 18.1.1affected

Default status: unknown

CVE ListBefore 15.1.1affected
Before 15.1affected

Default status: unknown

CVE ListBefore 2.1.1affected
Before 2.1affected

Default status: unknown

CVE ListBefore 17.7affected
18.0 to < 18.1affected

Default status: unknown

CVE ListBefore 17.7affected
18.0 to < 18.1affected

Proofs of concept

1

Repository PoCs

GitHubmigopp/cve-2024-44308Repository PoCby migoppStars: 0Not analyzed15 files

1.4 MiB

GitHub

PoC details

References

9