November 20, 2024Ravi LakshmananZero Day / Weakness

Apple Zero Day Threats

Apple has released security updates for iOS, iPadOS, macOS, VisionOS and its Safari web browser to address two zero-day vulnerabilities that have been actively exploited in the wild. .

The flaws are listed below-

  • CVE-2024-44308 – A vulnerability in JavaScriptCore that could lead to arbitrary code execution when processing malicious web content.
  • CVE-2024-44309 – A cookie management vulnerability in WebKit that could lead to a cross-site scripting (XSS) attack when processing malicious web content.
Cybersecurity

The iPhone maker said it addressed CVE-2024-44308 and CVE-2024-44309 with improved checks and improved state management, respectively.

Not much is known about the exact nature of the exploit, but Apple has acknowledged that the pair of vulnerabilities “can be actively exploited on Intel-based Mac systems.”

Clement Lecigne and Benoît Sevens of Google’s Threat Analysis Group (TAG) are credited with discovering and reporting the two vulnerabilities, which indicate they may be government-sponsored or sponsored. was used as part of spyware attacks.

Updates are available for the following devices and operating systems.

  • iOS 18.1.1 and iPadOS 18.1.1 – iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
  • iOS 17.7.2 and iPadOS 17.7.2 – iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later I, iPad 6th generation and later, and iPad mini 5th generation and later
  • macOS Sequoia 15.1.1 – Macs running macOS Sequoia
  • visionOS 2.1.1 – Apple Vision Pro
  • Safari 18.1.1 – Running macOS Ventura and macOS Sonoma.
Cybersecurity

Apple has addressed a total of four zero days in its software so far this year, including one (CVE-2024-27834) which was demonstrated at the Pwn2Own Vancouver hacking competition. The other three were slapped. January And March 2024.

Users are advised to update their devices to the latest version as soon as possible to avoid potential threats.

Did you find this article interesting? Follow us. Twitter And LinkedIn To read more exclusive content we post.





Source link