Apple has released urgent security updates for both macOS and iOS following the discovery of two vulnerabilities actively being exploited in the wild. These vulnerabilities, credited to Google’s Threat Analysis Group (TAG), are affecting Intel-based macOS systems and have prompted Apple to push out fixes quickly.
The vulnerabilities, identified as CVE-2024-44308 and CVE-2024-44309, target critical components within Apple's operating systems: JavaScriptCore and WebKit. Here's a closer look at the raw details of these vulnerabilities:
While Apple has acknowledged the active exploitation of these vulnerabilities, details on the specific attacks or indicators of compromise (IOCs) to help defenders detect infections have not been provided, which is typical in such security responses.
As a result, Apple is urging users across its ecosystem to immediately apply the following updates:
These updates are designed to patch the vulnerabilities and protect users from the ongoing exploitation attempts.
This latest patch comes on the heels of another concerning cybersecurity threat targeting macOS users. Earlier this month, North Korean cryptocurrency thieves were discovered launching a new malware campaign aimed at stealing digital assets. This attack involved phishing emails, fake PDF applications, and a novel technique designed to bypass Apple's security measures.
The active exploitation of these vulnerabilities and the rise in targeted malware campaigns highlight the increasing risks facing macOS users. Apple’s swift response with critical updates underscores the need for all users to stay vigilant and apply patches as soon as they become available.