logo

Apple Urgently Patches Actively Exploited Zero-Days

ID: 5e4cbaa2-f377-52da-a79e-17e5ca9f0678

STIX ID: report--5e4cbaa2-f377-52da-a79e-17e5ca9f0678

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-11-20

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Apple released security updates to remediate two zero-day vulnerabilities under active exploitation: CVE-2024-44308 (JavaScriptCore—possible arbitrary code execution, CVSS 6.8) and CVE-2024-44309 (WebKit cookie management leading to XSS, CVSS 4.3). The flaws impact iOS, iPadOS, macOS, visionOS, and Safari; they were reported by Google TAG and Apple confirmed possible in-the-wild exploitation (noting Intel-based Macs) but provided no IoCs. Users should update to the patched versions (iOS 18.1.1, macOS Sequoia 15.1.1, iOS 17.7.2) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.