Skip to content
COOEY

EXPOSURES › CVE-2024-44308

CVE-2024-44308

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-44308 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chain

Apple devices are actively exploited via a remote code execution vulnerability in web content processing.

CVE-2024-44308 allows arbitrary code execution on iOS, macOS, and other Apple products through malicious web content, and is currently listed in the CISA KEV program. DIB organizations must ensure all Apple hardware is patched immediately to prevent unauthorized access to sensitive systems and potential data exfiltration. Failure to patch exposes organizations to ransomware attacks and compliance violations under FedRAMP and NIST 800-171.

Shame score — The vulnerability is actively exploited in the wild and affects a wide range of Apple products, creating significant risk for DIB organizations relying on Apple hardware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.