
Apple has released security patches to address vulnerabilities in its products that are being actively exploited by cybercriminals
The first vulnerability tracked as CVE-2024-44308 stems in the JavaScriptCore component. Processing maliciously crafted web content may lead to arbitrary code execution. This means that an attacker will have to trick a victim into opening a malicious file containing web content.
The second vulnerability tracked as the CVE-2024-44309 is a cookie management issue in the WebKit component was addressed with improved state management.Processing maliciously crafted web content may lead to a cross-site scripting attack.
Both vulnerabilities haven’t been assigned a CVSS score. Apple does not share details until everyone has had a chance to update.
The fixes are included in the iOS 18.1.1 and iPadOS 18.1.1, Safari 18.1.1, visionOS 2.1.1 and macOS Sequoia 15.1.1 updates, available across a range of Apple devices, including iPhones, iPads, macOS and Apple Vision Pro.


