KEV · Actively exploited
CVE-2024-44308
CVE-2024-44308 is actively exploited (CISA KEV catalog) : high severity (CVSS 8.8), 0 tracked apps concerned, none still exposed on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- Confirmed
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 10.1 %
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
Show raw CVSS vector
CISA Known Exploited Vulnerability
- Added to KEV
- 2024-11-21
- Remediation deadline
- 2024-12-12
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Ransomware
- Unknown (not documented by CISA)
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.