← Back

CVE-2024-44309

nvd nist
Published: Nov 20, 2024Modified: Apr 3, 2026CISA KEV

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

Affected (8)

1 product
Debian Linux
5 products
Ipados
Iphone Os
Macos
Safari
Visionos
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Before 17.7.2
From 18.0 to 18.1.1
Apple
Before 17.7.2
From 18.0 to 18.1.1
From 15.0 to 15.1.1
Before 18.1.1
Before 2.1.1

References (8)

Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.