{"id":60468,"date":"2024-11-23T17:50:34","date_gmt":"2024-11-23T14:50:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182747\/APPLE-SA-11-19-2024-4.txt"},"modified":"2024-11-23T17:50:34","modified_gmt":"2024-11-23T14:50:34","slug":"apple-security-advisory-11-19-2024-4","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-11-19-2024-4\/","title":{"rendered":"Apple Security Advisory 11-19-2024-4"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2<\/p>\n<p>iOS 17.7.2 and iPadOS 17.7.2 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121754.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>JavaScriptCore<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Processing maliciously crafted web content may lead to arbitrary<br \/>code execution. Apple is aware of a report that this issue may have been<br \/>actively exploited on Intel-based Mac systems.<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 283063<br \/>CVE-2024-44308: Cl\u00e9ment Lecigne and Beno\u00eet Sevens of Google&#8217;s Threat<br \/>Analysis Group<\/p>\n<p>WebKit<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Processing maliciously crafted web content may lead to a cross<br \/>site scripting attack. Apple is aware of a report that this issue may<br \/>have been actively exploited on Intel-based Mac systems.<br \/>Description: A cookie management issue was addressed with improved state<br \/>management.<br \/>WebKit Bugzilla: 283095<br \/>CVE-2024-44309: Cl\u00e9ment Lecigne and Beno\u00eet Sevens of Google&#8217;s Threat<br \/>Analysis Group<\/p>\n<p>This update is available through iTunes and Software Update on your<br \/>iOS device, and will not appear in your computer&#8217;s Software Update<br \/>application, or in the Apple Downloads site. Make sure you have an<br \/>Internet connection and have installed the latest version of iTunes<br \/>from https:\/\/www.apple.com\/itunes\/<\/p>\n<p>iTunes and Software Update on the device will automatically check<br \/>Apple&#8217;s update server on its weekly schedule. When an update is<br \/>detected, it is downloaded and the option to be installed is<br \/>presented to the user when the iOS device is docked. We recommend<br \/>applying the update immediately if possible. Selecting<br \/>Don&#8217;t Install will present the option the next time you connect<br \/>your iOS device.<\/p>\n<p>The automatic update process may take up to a week depending on<br \/>the day that iTunes or the device checks for updates. You may<br \/>manually obtain the update via the Check for Updates button<br \/>within iTunes, or the Software Update on your device.<\/p>\n<p>To check that the iPhone, iPod touch, or iPad has been updated:<\/p>\n<p>* Navigate to Settings<br \/>* Select General<br \/>* Select About. The version after applying this update will be<br \/>&#8220;iOS 17.7.2 and iPadOS 17.7.2&#8221;.<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmc9JGcACgkQX+5d1TXa<br \/>IvqaMhAArOKmA61hgLNGofjznuKQo6Jc42iPl7a\/ZiB2Tq5ynZKPIGmGiM3HdJQ8<br \/>bbifOgpkmNcA3h1OUlXnnkbdehq6d8MzI9WSn6uHdgWZ5LqLMXOWgsEF5Hwwmm7z<br \/>aqTaqMv4fV2J6w2wTcoL5XptxGXiEi37\/GzcureD3hvL+nRAAzR6c\/gRXmcEjGL7<br \/>pVTNJA0C8VyY9kG+Uc7ia2m5Riux2jsYzWYppPfCwUFeo3bQDexG7WsiHa00OZN+<br \/>HkNS5\/1t\/7hftJZ+w\/PbVnEK23Dm962NQgCrcFKGnbjNGJQlIjl+xfbi6BuQ6lJJ<br \/>ZAI+3WqPHXLAMCcae\/DfERqXWnJu8fTMfCwCbQVx185Cih+mtH0oc4MtPtiZdhi8<br \/>TxZpVGZHYjLJa9VANTrNzkAmFflnhAC4tAG2FXx3ld3t\/8u9Fhv0oyTa5HlzVYJ\/<br \/>WJgK32eT7I1h7Oqrp49KZcMIM8H6ZwNXYOI+Rf7GXdEN2y9Qhb+IOvdilTrCTpzR<br \/>l6Gu6fBwH0G0UGHRktnBPlryJdOg26J1iVBZg6\/K\/CSjQizWdDXN\/Nq4YwI17Eq4<br \/>HtFdtOtrs5n0bDz+fsfGbsieTyUz1BUet2xLzPECfD4nYEKmckD1d\/dRylc3vK9Y<br \/>GOCp1nWDoPSKnmkU9Il2SFAIuEM9o60lCN7PMWBrC9zYXMAxFmY=<br \/>=+VKC<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2 iOS 17.7.2 and iPadOS 17.7.2 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121754. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. JavaScriptCoreAvailable for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch2nd generation &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60468","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60468"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60468\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}