Exploitation Summary
CVE-2024-44308 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 21, 2024. EIP tracks 1 public exploit from researchers including migopp.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2024-44308, targeting a type confusion vulnerability in WebKit's JavaScript engine. The exploit leverages a SharedArrayBuffer with a growable buffer to trigger the bug, leading to arbitrary memory manipulation and potential remote code execution.
Description
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2024-44308, targeting a type confusion vulnerability in WebKit's JavaScript engine. The exploit leverages a SharedArrayBuffer with a growable buffer to trigger the bug, leading to arbitrary memory manipulation and potential remote code execution.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H