CVE-2024-44309

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

Researchers: Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group

Attribute Value
CVE CVE-2024-44309
Bugzilla 283095
Component WebKit
Bug Class LogicError
Severity medium
Commit 3845740eb3e24283…
Advisory Apple Advisory

Root Cause Analysis

A cookie management issue was addressed with improved state management.