Apple Urges Updates to Patch Active Zero-Day Exploits
by levi12 - Wednesday November 20, 2024 at 01:43 PM
#1
Apple has issued security updates to address two zero-day vulnerabilities affecting iOS, iPadOS, macOS, visionOS, and Safari. The flaws, already under active exploitation, are detailed as follows:
  • CVE-2024-44308: A JavaScriptCore vulnerability allowing arbitrary code execution via malicious web content.
  • CVE-2024-44309: A WebKit cookie management flaw enabling cross-site scripting (XSS) attacks through malicious web content.

The issues were resolved with improved checks and state management. Apple acknowledged that these vulnerabilities might have been exploited on Intel-based Mac systems. They were reported by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group, suggesting their use in targeted attacks, possibly involving government-backed spyware.

Updates Available for the Following:
-iOS 18.1.1 and iPadOS 18.1.1: For iPhone XS and later, and various iPad models.
[b]-iOS 17.7.2 and iPadOS 17.7.2: For older but still-supported devices like iPhone XS and iPad Pro (10.5-inch).[/b]

[b]-macOS Sequoia 15.1.1: For systems running macOS Sequoia.[/b]

[b]-visionOS 2.1.1: For Apple Vision Pro.[/b]

[b]-Safari 18.1.1: For macOS Ventura and Sonoma.[/b]

This marks the fourth zero-day Apple has addressed in 2024, including one from the Pwn2Own competition and others patched earlier this year. Users are strongly urged to update their devices immediately to stay protected.
Reply
#2
Can you add ur source plz
Reply
#3
(11-24-2024, 03:48 PM)KingDice Wrote: Can you add ur source plz

official website
https://support.apple.com/en-us/100100
Reply
#4
tnx man ppreciated
Reply
#5
(11-20-2024, 01:43 PM)levi12 Wrote: Apple has issued security updates to address two zero-day vulnerabilities affecting iOS, iPadOS, macOS, visionOS, and Safari. The flaws, already under active exploitation, are detailed as follows:
  • CVE-2024-44308: A JavaScriptCore vulnerability allowing arbitrary code execution via malicious web content.
  • CVE-2024-44309: A WebKit cookie management flaw enabling cross-site scripting (XSS) attacks through malicious web content.

The issues were resolved with improved checks and state management. Apple acknowledged that these vulnerabilities might have been exploited on Intel-based Mac systems. They were reported by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group, suggesting their use in targeted attacks, possibly involving government-backed spyware.

Updates Available for the Following:
-iOS 18.1.1 and iPadOS 18.1.1: For iPhone XS and later, and various iPad models.
[b]-iOS 17.7.2 and iPadOS 17.7.2: For older but still-supported devices like iPhone XS and iPad Pro (10.5-inch).[/b]

[b]-macOS Sequoia 15.1.1: For systems running macOS Sequoia.[/b]

[b]-visionOS 2.1.1: For Apple Vision Pro.[/b]

[b]-Safari 18.1.1: For macOS Ventura and Sonoma.[/b]

This marks the fourth zero-day Apple has addressed in 2024, including one from the Pwn2Own competition and others patched earlier this year. Users are strongly urged to update their devices immediately to stay protected.

It's concerning that these vulnerabilities have already been exploited in targeted attacks. Given that the issues affect multiple Apple devices, including Intel-based Macs, how can users ensure their systems are fully secure from this kind of threat, especially in light of potential government-backed spyware? Is there any additional advice on preventing such attacks beyond updating to the latest patches?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features KingDice 0 227 03-31-2025, 08:41 AM
Last Post: KingDice
  New Zyxel Zero-Day Under Attack, No Patch Available KingDice 0 508 02-02-2025, 08:10 AM
Last Post: KingDice
  Bad Tenable plugin updates take down Nessus agents worldwide KingDice 4 709 01-08-2025, 12:05 AM
Last Post: 025123118081096
  Nvidia set to overtake Apple as world's second-most valuable company Chapo 3 835 08-04-2024, 10:33 PM
Last Post: Searchit
  New CVE Exploits Target Apache Web Server and VMware ESXi CrazyDwarf2 2 1,585 10-03-2023, 02:02 PM
Last Post: ghost-worm

Forum Jump:


 Users browsing this thread: 1 Guest(s)