Apple Urgently Patches Actively Exploited Zero-Days
ID: 5e4cbaa2-f377-52da-a79e-17e5ca9f0678
STIX ID: report--5e4cbaa2-f377-52da-a79e-17e5ca9f0678
Feed Name: Dark Reading
Apple released security updates to remediate two zero-day vulnerabilities under active exploitation: CVE-2024-44308 (JavaScriptCore—possible arbitrary code execution, CVSS 6.8) and CVE-2024-44309 (WebKit cookie management leading to XSS, CVSS 4.3). The flaws impact iOS, iPadOS, macOS, visionOS, and Safari; they were reported by Google TAG and Apple confirmed possible in-the-wild exploitation (noting Intel-based Macs) but provided no IoCs. Users should update to the patched versions (iOS 18.1.1, macOS Sequoia 15.1.1, iOS 17.7.2) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
