Apple Releases Urgently Patches Actively Exploited Zero-Days

Apple releases emergency security updates to address two critical zero-day vulnerabilities that could allow attackers to compromise iPhones, iPads, and Macs.

The vulnerabilities, tracked as CVE-2024-44308 and CVE-2024-44309, were actively exploited by attackers. The first flaw, a JavaScript Core vulnerability, could potentially lead to remote code execution, while the second, a WebKit vulnerability, could enable cross-site scripting (XSS) attacks.

Apple Releases

Affected Devices and Operating Systems in Apple Releases:

  • iOS and iPadOS:
    • iOS 18.1.1 and iPadOS 18.1.1
    • iOS 17.7.2 and iPadOS 17.7.2
  • macOS:
    • macOS Sonoma 15.1.1
  • visionOS:
    • visionOS 2.1.1
  • Safari:
    • Safari 18.1.1

While Apple hasn’t disclosed specific details about the attacks, the company has confirmed that the vulnerabilities were actively exploited on Intel-based Macs. Security researchers Clément Lecigne and Benoît Sevens from Google’s Threat Analysis Group (TAG) discovered and reported the flaws, suggesting that they were likely used in sophisticated, targeted attacks, possibly by state-sponsored or mercenary hacking groups.

Apple releases addressed these vulnerabilities by implementing improved checks and state management in the affected software.

Recommended Action:

Apple strongly encourages users to update their devices to the latest versions as soon as possible to protect against these vulnerabilities. After Apple releases Users can check for updates by going to Settings > General > Software Update on their iOS or iPadOS devices, or System Preferences > Software Update on their Macs.

 

Meta Techs: Your Cybersecurity Partner

At Meta Techs, we understand the importance of staying up-to-date with the latest security patches. Our team of experts can help you:

  • Identify and Assess Vulnerabilities: Conduct regular security assessments to identify and address potential threats.
  • Implement Security Best Practices: Advise on and implement best practices to protect your devices and data.
  • Stay Informed: Keep you updated on the latest security threats and vulnerabilities.
  • Rapid Incident Response: Respond quickly and effectively to security incidents.

By partnering with Meta Techs, you can ensure the security of your Apple devices and protect your sensitive information.

 

More articles