Skip to content
COOEY

EXPOSURES › CVE-2024-44309

CVE-2024-44309

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-44309 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Apple's iOS and macOS products contain an actively exploited XSS vulnerability that allows attackers to inject malicious scripts into web content.

This cross-site scripting (XSS) vulnerability in Apple's iOS and macOS products allows attackers to inject malicious scripts into web content, potentially leading to credential theft or session hijacking. For DIB organizations, this poses a significant risk as Apple devices are widely used in government and defense environments, and the vulnerability is actively being exploited in the wild. Organizations should immediately update to patched versions of iOS and macOS and implement additional web content filtering to mitigate the risk.

Shame score — While the vulnerability is actively exploited, it is a common XSS issue that Apple has disclosed and patched, making it less avoidable than negligent security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.