News

MacOS Sequoia 15.1.1: Critical Security Update Addresses Web-Based Vulnerabilities

Giulio Saggin
Giulio Saggin
Thursday 21 November 2024
MacOS Sequoia 15.1.1: Critical Security Update Addresses Web-Based Vulnerabilities
Photo: Jimmy Jin (unsplash)

Apple has released macOS Sequoia 15.1.1, a security update addressing two significant vulnerabilities that could potentially expose Mac users to security risks. Released on November 19, 2024, this update focuses on critical improvements in web content processing and browser security.

JavaScriptCore Vulnerability (CVE-2024-44308) The first critical security issue involves JavaScriptCore, Apple's JavaScript engine. Researchers from Google's Threat Analysis Group, Clément Lecigne and Benoît Sevens, discovered a vulnerability that could allow arbitrary code execution through maliciously crafted web content.

WebKit Cookie Management Vulnerability (CVE-2024-44309) The second vulnerability affects WebKit, the web browser engine used across Apple platforms. This issue could enable cross-site scripting (XSS) attacks through manipulation of cookie management processes.

Recommendations for users:

1. Update to macOS Sequoia 15.1.1 immediately 2. Enable automatic system updates 3. Be cautious when browsing unfamiliar websites 4. Keep all applications and browsers updated

(Credit: Clément Lecigne and Benoît Sevens from Google's Threat Analysis Group reported these vulnerabilities.)

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203