EXPOSURES › CVE-2024-44308
CVE-2024-44308
HIGH ⌖ ON CISA KEV · EXPLOITEDApple devices are actively exploited via a remote code execution vulnerability in web content processing.
CVE-2024-44308 allows arbitrary code execution on iOS, macOS, and other Apple products through malicious web content, and is currently listed in the CISA KEV program. DIB organizations must ensure all Apple hardware is patched immediately to prevent unauthorized access to sensitive systems and potential data exfiltration. Failure to patch exposes organizations to ransomware attacks and compliance violations under FedRAMP and NIST 800-171.
Shame score — The vulnerability is actively exploited in the wild and affects a wide range of Apple products, creating significant risk for DIB organizations relying on Apple hardware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.