Zum Inhalt der Seite gehen


Apple fixes 2 Zero-Days exploited to breach MacOS Systems. :apple_inc:

Apple has released emergency security updates for macOS Sequoia that fix two zero-day vulnerabilities that “may have been actively exploited on Intel-based Mac systems”. As per usual, Apple didn’t share details about the attacks in which patched vulnerabilities are exploited.

[CVE-2024-44309 & CVE-2024-44308]

https://support.apple.com/en-us/121753

#apple #macos #update #it #security #privacy #engineer #media #tech #news
Apple has transitioned to using Intel processors on Macs in June 2006 and stopped shipping them altogether in June 2023, after starting using its own silicon in 2020.

The two vulnerabilities “may have been actively exploited on Intel-based Mac systems”, but it’s unclear at this time whether that means that they can’t be exploited on Apple-based Macs.

[⚠️In any case, all MacOS Sequoia users should update their systems as soon as possible.⚠️]

CVE-2024-44309 affects WebKit, the browser engine used in the Safari web browser and all iOS and iPadOS web browsers, and can be triggered when it’s made to process maliciously crafted web content. It can enable a cross site scripting (XSS) attack.

CVE-2024-44308 affects JavaScriptCore (the built-in JavaScript engine for WebKit) and can likewise be exploited via maliciously crafted web content. It can lead to arbitrary code execution.

<Both vulnerabilities have been reported by security researchers Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group (TAG).>
Apple has also released security patches for iOS, iPadOS, visionOS and its Safari web browser. The updates are available for the following devices and operating systems:

• iOS 18.1.1 and iPadOS 18.1.1 - iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
<https://support.apple.com/en-us/121752>
• iOS 17.7.2 and iPadOS 17.7.2 - iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
<https://support.apple.com/en-us/121754>
• macOS Sequoia 15.1.1 - Macs running macOS Sequoia
<https://support.apple.com/en-us/121753>
• visionOS 2.1.1 - Apple Vision Pro
<https://support.apple.com/en-us/121755>
• Safari 18.1.1 - Macs running macOS Ventura and macOS Sonoma
<https://support.apple.com/en-us/121756>