HIGH

CVE-2024-44308

Debian Debian Linux 2024-11-20 CVSS v3.1
CVSS
8.8
KEV

Description

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

Summary dbcve.org

A WebKit vulnerability allowing arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks, suggesting a validation bypass in WebKit's content processing. This is being actively exploited in the wild against Intel-based Mac systems.

Mitigation

Apply vendor patches immediately: update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1, or visionOS 2.1.1 as appropriate for affected devices.

EPSS Score

10.16%
Probability of exploitation in next 30 days
95.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE