Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosGoogle Cloud Tech: Vibe coding in the pit lane 🏁(23.09.2026 um 01:00 Uhr)
Sichere ProgrammierungBuild an Explainable Vendor-Risk Gate in Node.js(23.09.2026 um 00:27 Uhr)
Sichere ProgrammierungFrom p=none to Enforcement: A Working Sequence for DMARC Rollout(23.09.2026 um 00:40 Uhr)
Sichere ProgrammierungWhen OPA's Bundle Loader Runs Past a `.manifest` Typo(23.09.2026 um 00:53 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: Bybit(23.09.2026 um 01:00 Uhr)
Linux Tipps & HardeningOpenShot video editor is now available as a snap(23.09.2026 um 00:09 Uhr)
KI & AI VideosAI Revolution: AI Robots Are Beating Humans Now(23.09.2026 um 00:32 Uhr)
YouTube Security VideosGoogle Cloud Tech: Vibe coding in the pit lane 🏁(23.09.2026 um 01:00 Uhr)
Sichere ProgrammierungBuild an Explainable Vendor-Risk Gate in Node.js(23.09.2026 um 00:27 Uhr)
Sichere ProgrammierungFrom p=none to Enforcement: A Working Sequence for DMARC Rollout(23.09.2026 um 00:40 Uhr)
Sichere ProgrammierungWhen OPA's Bundle Loader Runs Past a `.manifest` Typo(23.09.2026 um 00:53 Uhr)
Sichere ProgrammierungGovernance Attack Surface Review: Bybit(23.09.2026 um 01:00 Uhr)
Linux Tipps & HardeningOpenShot video editor is now available as a snap(23.09.2026 um 00:09 Uhr)
KI & AI VideosAI Revolution: AI Robots Are Beating Humans Now(23.09.2026 um 00:32 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Apple Rushes to Patch Two Zero-Day Exploits Targeting Intel-Based Macs

Apple Rushes to Patch Two Zero-Day Exploits Targeting Intel-Based Macs Post Views:…

0
↗ Quelle (blackhatethicalhacking.com)
Reagiere als Erste:r — dein Feedback zählt!

























Apple Rushes to Patch Two Zero-Day Exploits Targeting Intel-Based Macs



















































Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.







Patreon

















Reading Time: 3 Minutes


















Apple has released emergency security updates to patch two actively exploited zero-day vulnerabilities targeting Intel-based macOS systems. The vulnerabilities affect the JavaScriptCore and WebKit components, both of which are critical to macOS and other Apple operating systems.



Details of the Vulnerabilities




  1. CVE-2024-44308 (JavaScriptCore)



    • Impact: Remote Code Execution (RCE).

    • Description: Allows attackers to execute arbitrary code through maliciously crafted web content.

    • Component: JavaScriptCore, a fundamental part of macOS used to process JavaScript in Safari and other Apple applications.




  2. CVE-2024-44309 (WebKit)



    • Impact: Cross-Site Scripting (XSS).

    • Description: Enables cross-site scripting (CSS) attacks, potentially compromising sensitive data and user sessions.









See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses



















Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.








Affected Systems and Fixes


Apple has addressed these issues in the following updates:



  • macOS: Fixed in macOS Sequoia 15.1.1.

  • iOS/iPadOS: Patched in iOS and iPadOS 17.7.2 and 18.1.1.

  • visionOS: Updated to 2.1.1.


The vulnerabilities were reported by Clément Lecigne and Benoît Sevens from Google’s Threat Analysis Group (TAG), which specializes in identifying zero-days and targeted exploits.



Exploitation in the Wild


Apple has acknowledged that the flaws were exploited in attacks, particularly targeting Intel-based Macs, but specific details remain scarce. Google TAG, which discovered the flaws, has also withheld further insights into exploitation methods.



















Apple Zero-Days in 2024


The patching of these vulnerabilities brings the total number of zero-day fixes by Apple in 2024 to six, significantly fewer than the 20 zero-days addressed in 2023. Apple has been steadily improving its detection and mitigation of such issues, reducing exploit opportunities compared to prior years.



Recommendations




  1. Update Immediately:



    • Ensure macOS is updated to 15.1.1 (Sequoia).

    • Update iPhones and iPads to the latest iOS and iPadOS versions (17.7.2 or 18.1.1).

    • visionOS users should upgrade to 2.1.1.




  2. Enable Auto-Updates: Enable automatic updates for all Apple devices to minimize exposure to newly discovered vulnerabilities.




  3. Exercise Caution with Web Content: As the vulnerabilities involve web exploitation, users should avoid suspicious websites or untrusted links until systems are fully updated.










Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]








Source: bleepingcomputer.com


Source Link







Merch




















Offensive Security & Ethical Hacking Course


Begin the learning curve of hacking now!




Information Security Solutions


Find out how Pentesting Services can help you.




Join our Community






The post Apple Rushes to Patch Two Zero-Day Exploits Targeting Intel-Based Macs first appeared on Black Hat Ethical Hacking.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Apple Rushes to Patch Two Zero-Day Exploits Targeting Intel-Based Macs

Thematisch verwandte Begriffe: Apple, Rushes, Patch, ZeroDay · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-58268 | SIPGO is a library for writing SIP services in the GO language. Prior to…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick