Apple has launched iOS 18.1.1 and macOS Sequoia 15.1.1, which include significant security updates. The company has elaborated on these vulnerabilities on its security page, stating that they might have been actively exploited in real-world scenarios.
According to Apple, iOS 18.1.1, iPadOS 18.1.1, and macOS Sequoia 15.1.1 resolve two vulnerabilities that impact WebKit and JavaScriptCore. The company has noted awareness of “a report indicating that this issue may have been actively exploited on Intel-based Mac systems.”
JavaScriptCore
- Compatible with: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and newer, iPad Pro 11-inch 1st generation and newer, iPad Air 3rd generation and newer, iPad 7th generation and newer, and iPad mini 5th generation and newer.
- Risk: Processing specially crafted web content may permit arbitrary code execution. Apple is aware of a report indicating that this issue may have been actively exploited on Intel-based Mac systems.
- Resolution: The issue was resolved through enhanced validation procedures.
- CVE-2024-44308: Acknowledged by Clément Lecigne and Benoît Sevens from Google’s Threat Analysis Group.
WebKit
- Compatible with: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and newer, iPad Pro 11-inch 1st generation and newer, iPad Air 3rd generation and newer, iPad 7th generation and newer, and iPad mini 5th generation and newer.
- Risk: Handling maliciously designed web content may lead to a cross-site scripting attack. Apple is aware of a report indicating that this issue may have been actively exploited on Intel-based Mac systems.
- Resolution: A problem related to cookie management was resolved by improving state management.
- CVE-2024-44309: Acknowledged by Clément Lecigne and Benoît Sevens from Google’s Threat Analysis Group.
To update your iPhone or iPad to iOS 18.1.1 or iPadOS 18.1.1, open the Settings app, select General, and then tap Software Update.
To upgrade your Mac to macOS Sequoia 15.1.1, navigate to System Settings, select General, and then click Software Update.
Even though Apple states that these issues have only been exploited on Intel-based Macs thus far, it is imperative that you promptly update your devices to safeguard against these vulnerabilities.
: . More.