Skip to main content

Multiple vulnerabilities affect macOS Sequoia, iOS, iPadOS, Safari, and visionOS

Summary

Multiple vulnerabilities affect macOS Sequoia, iOS, iPadOS, Safari, and visionOS

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Apple has released security updates to address two vulnerabilities in multiple Apple products.

The vulnerability CVE-2024-44308 is a weakness in JavaScriptCore when processing of maliciously crafted web content. Successful exploitation by an attacker could cause arbitrary code execution

The second vulnerability CVE-2024-44309 is a vulnerability that impacts cookie management in WebKit that can may lead to a cross-site scripting attack during the processing of maliciously crafted web content.

Remediation advice

Affected organisations are encouraged to review Apple security releases and apply the relevant updates.

Remediation steps

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 20 November 2024 4:15 pm