Cyber Resilience

CVE-2024-44308

Apple Ipados ≤ 17.7.2

CISA KEVActive ExploitationEUVD Exploited
Published
20 November 2024
Modified
03 April 2026
KEV Added
21 November 2024
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.092 95th percentile
Risk Priority 90 floored blend · peak EPSS

Summary

CVE-2024-44308 is a high-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2024-44308 is a vulnerability in Apple's web content processing components that was addressed through improved input validation checks. It affects Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, and visionOS 2.1.1. The flaw permits arbitrary code execution when maliciously crafted web content is processed, and carries a CVSS 3.1 score of 8.8 reflecting network attack vector, low complexity, and no required privileges.

An unauthenticated remote attacker can exploit the issue by serving malicious web content that a victim visits or renders, resulting in full arbitrary code execution on the target system with impacts to confidentiality, integrity, and availability. User interaction is required in the form of processing the crafted content.

Apple security advisories for the listed products confirm that the fixes are delivered via the updated releases and note that the issue may have been actively exploited in the wild against Intel-based Mac systems. The EPSS score rose from a low starting value to a recorded peak of 0.0186, indicating emerging post-disclosure exploitation interest that warrants renewed attention.

EU & UK References

Vulnerability Data

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution.…

more

Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CWE(s)
KEV Date Added
21 November 2024

Related Threats

CVEs Like This One

CVE-2024-44309Same product: Apple Ipadosboth on KEV
CVE-2025-24201Same product: Apple Ipadosboth on KEV
CVE-2024-23222Same product: Apple Ipadosboth on KEV
CVE-2021-30858Same product: Apple Ipadosboth on KEV
CVE-2023-28205Same product: Apple Ipadosboth on KEV
CVE-2023-32435Same product: Apple Ipadosboth on KEV
CVE-2022-22620Same product: Apple Ipadosboth on KEV
CVE-2023-23529Same product: Apple Ipadosboth on KEV
CVE-2023-42917Same product: Apple Ipadosboth on KEV
CVE-2021-1871Same product: Apple Ipadosboth on KEV

Affected Assets

debian
debian linux
11.0
apple
safari
≤ 18.1.1
apple
ipados
≤ 17.7.2 · 18.0 — 18.1.1
apple
iphone os
≤ 17.7.2 · 18.0 — 18.1.1
apple
macos
15.0 — 15.1.1
apple
visionos
≤ 2.1.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References