seclists.org
http://seclists.org/fulldisclosure/2024/Nov/16 CVE-2024-44308
HIGHCISA KEV
Apple Multiple Products Code Execution Vulnerability
Record summary
CVE-2024-44308 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2024-44308 in KEV.
Description
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 21, 2024 · CISA
- VulnCheck KEV
- Listed · Nov 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 23, 2024 · Source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
SafariBrowse Apple / SafariDefault status: unknown | CVE List | Before 18.1.1 | affected |
| Before 18.1 | affected | ||
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 17.7.2 | affected |
| Before 18.1.1 | affected | ||
macOSBrowse Apple / macOSDefault status: unknown | CVE List | Before 15.1.1 | affected |
| Before 15.1 | affected | ||
visionOSBrowse Apple / visionOSDefault status: unknown | CVE List | Before 2.1.1 | affected |
| Before 2.1 | affected | ||
ipad_osBrowse apple / ipad_osDefault status: unknown | CVE List | Before 17.7 | affected |
| 18.0 to < 18.1 | affected | ||
iphone_osBrowse apple / iphone_osDefault status: unknown | CVE List | Before 17.7 | affected |
| 18.0 to < 18.1 | affected | ||
Proofs of concept
1Repository PoCs
GitHubmigopp/cve-2024-44308Repository PoCby migoppStars: 0Not analyzed15 files
References
9lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/12/msg00003.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-44308 support.apple.com
https://support.apple.com/en-us/121752 support.apple.com
https://support.apple.com/en-us/121753 support.apple.com
https://support.apple.com/en-us/121754 support.apple.com
https://support.apple.com/en-us/121755 support.apple.com
https://support.apple.com/en-us/121756 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-44308