Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Dec 12, 2024

CVE-2024-44309

High
EPSS 1.2%CISA KEV
Apple/Multiple Products

Description

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.

EPSS — Exploit Probability

1.2%

Higher than 78.7% of all CVEs

Required Action

https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, https://support.apple.com/en-us/121754, https://support.apple.com/en-us/121755, https://support.apple.com/en-us/121756 ; https://nvd.nist.gov/vuln/detail/CVE-2024-44309

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
1.2%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 21, 2024

Added to KEV

Nov 21, 2024

Remediation Due

Dec 12, 2024

Affected Product

Apple

Multiple Products

View all Apple CVEs