Exploits

Apple Patches Two Actively Exploited Zero-Day Vulnerabilities in Latest Updates

Published  ·  2 min read

Apple has rolled out security updates for its operating systems and Safari browser to address two actively exploited zero-day vulnerabilities. The flaws—discovered by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group (TAG)—highlight the importance of timely software updates to mitigate sophisticated cyber threats.

Details of the Vulnerabilities

  1. CVE-2024-44308
    1. Component: JavaScriptCore
    2. Impact: Arbitrary code execution
    3. Cause: Processing of malicious web content
    4. Fix: Improved checks
  1. CVE-2024-44309
    1. Component: WebKit
    2. Impact: Cross-site scripting (XSS) attacks
    3. Cause: Flawed cookie management
    4. Fix: Improved state management

Apple noted that these vulnerabilities might have been actively exploited, particularly on Intel-based Mac systems, potentially as part of highly-targeted spyware campaigns.

Updates Released

  1. iOS and iPadOS
    1. Version 18.1.1: iPhone XS and newer, iPads from 7th generation and newer
    2. Version 17.7.2: iPhone XS and newer, iPads from 6th generation and newer
  2. macOS : Sequoia 15.1.1: All Macs running macOS Sequoia
  3. visionOS : Version 2.1.1: Apple Vision Pro
  4. Safari : Version 18.1.1: Macs with macOS Ventura and Sonoma

Why It Matters

These updates underscore the critical nature of addressing zero-day vulnerabilities, particularly those potentially exploited by advanced threat actors in targeted attacks. Exploitation of these flaws could result in arbitrary code execution or data compromise, impacting device security and user privacy.

Apple has patched four zero-days in 2024, including a notable one (CVE-2024-27834) demonstrated at Pwn2Own Vancouver.

How to Stay Protected

  1. Update Your Devices:
    Install the latest software updates for iOS, iPadOS, macOS, visionOS, and Safari.
  2. Be Cautious with Web Content:
    Avoid clicking on unknown or suspicious links.
  3. Enable Automatic Updates:
    Ensure your devices are configured to receive updates as soon as they are available.
  4. Regularly Monitor Device Security:
    Stay informed about updates and vulnerabilities to keep your devices secure.

Apple’s swift response to CVE-2024-44308 and CVE-2024-44309 demonstrates its commitment to user security. Update your devices immediately to guard against these actively exploited vulnerabilities.

 

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067