First published: Tue Nov 19 2024(Updated: )
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
Credit: product-security@apple.com Clément Lecigne Google's Threat Analysis GroupBenoît Sevens Google's Threat Analysis Group
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Multiple Products | ||
debian/webkit2gtk | <=2.44.2-1~deb11u1<=2.46.0-2~deb12u1 | 2.46.4-1~deb11u1 2.46.4-1~deb12u1 2.46.4-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.46.4-1 |
Apple macOS Sequoia | <15.1.1 | 15.1.1 |
Apple Mobile Safari | <18.1.1 | 18.1.1 |
Apple Mobile Safari | <18.1.1 | |
Apple iOS, iPadOS, and watchOS | <17.7.2 | |
Apple iOS, iPadOS, and watchOS | >=18.0<18.1.1 | |
iOS | <17.7.2 | |
iOS | >=18.0<18.1.1 | |
Apple iOS and macOS | <15.1.1 | |
visionOS | <2.1.1 | |
Apple iOS, iPadOS, and watchOS | <17.7.2 | 17.7.2 |
Apple iOS, iPadOS, and watchOS | <17.7.2 | 17.7.2 |
Apple iOS, iPadOS, and watchOS | <18.1.1 | 18.1.1 |
Apple iOS, iPadOS, and watchOS | <18.1.1 | 18.1.1 |
visionOS | <2.1.1 | 2.1.1 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2024-44308 is classified as a critical vulnerability that may allow arbitrary code execution.
To fix CVE-2024-44308, update your affected Apple product to the latest version available, as specified in the remediation section.
CVE-2024-44308 affects various Apple products including iOS, iPadOS, macOS, and Safari up to specific versions.
CVE-2024-44308 is an unspecified vulnerability linked to the processing of maliciously crafted web content.
The issue was addressed with improved checks to enhance the security of the affected products.