216.73.217.80

CVE-2024-44308

· Published 20/11/2024 00:15 · Modified 27/11/2024 19:35

Labels: CVE-2024-44308 2024-11-20CVE-2024-44308NVD-CWE-noinfo[email protected]

Essential information

Published
20/11/2024 00:15
Modified
27/11/2024 19:35
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apple / safari cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
apple / ipados cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple / ipados cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple / iphone os cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple / iphone os cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple / macos cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple / visionos cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

References