{"id":60475,"date":"2024-11-23T22:41:00","date_gmt":"2024-11-23T19:41:00","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182743\/APPLE-SA-11-19-2024-3.txt"},"modified":"2024-11-23T22:41:00","modified_gmt":"2024-11-23T19:41:00","slug":"apple-security-advisory-11-19-2024-3","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-11-19-2024-3\/","title":{"rendered":"Apple Security Advisory 11-19-2024-3"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1<\/p>\n<p>iOS 18.1.1 and iPadOS 18.1.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121752.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>JavaScriptCore<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>3rd generation and later, iPad Pro 11-inch 1st generation and later,<br \/>iPad Air 3rd generation and later, iPad 7th generation and later, and<br \/>iPad mini 5th generation and later<br \/>Impact: Processing maliciously crafted web content may lead to arbitrary<br \/>code execution. Apple is aware of a report that this issue may have been<br \/>actively exploited on Intel-based Mac systems.<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 283063<br \/>CVE-2024-44308: Cl\u00e9ment Lecigne and Beno\u00eet Sevens of Google&#8217;s Threat<br \/>Analysis Group<\/p>\n<p>WebKit<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>3rd generation and later, iPad Pro 11-inch 1st generation and later,<br \/>iPad Air 3rd generation and later, iPad 7th generation and later, and<br \/>iPad mini 5th generation and later<br \/>Impact: Processing maliciously crafted web content may lead to a cross<br \/>site scripting attack. Apple is aware of a report that this issue may<br \/>have been actively exploited on Intel-based Mac systems.<br \/>Description: A cookie management issue was addressed with improved state<br \/>management.<br \/>WebKit Bugzilla: 283095<br \/>CVE-2024-44309: Cl\u00e9ment Lecigne and Beno\u00eet Sevens of Google&#8217;s Threat<br \/>Analysis Group<\/p>\n<p>This update is available through iTunes and Software Update on your<br \/>iOS device, and will not appear in your computer&#8217;s Software Update<br \/>application, or in the Apple Downloads site. Make sure you have an<br \/>Internet connection and have installed the latest version of iTunes<br \/>from https:\/\/www.apple.com\/itunes\/<\/p>\n<p>iTunes and Software Update on the device will automatically check<br \/>Apple&#8217;s update server on its weekly schedule. When an update is<br \/>detected, it is downloaded and the option to be installed is<br \/>presented to the user when the iOS device is docked. We recommend<br \/>applying the update immediately if possible. Selecting<br \/>Don&#8217;t Install will present the option the next time you connect<br \/>your iOS device.<\/p>\n<p>The automatic update process may take up to a week depending on<br \/>the day that iTunes or the device checks for updates. You may<br \/>manually obtain the update via the Check for Updates button<br \/>within iTunes, or the Software Update on your device.<\/p>\n<p>To check that the iPhone, iPod touch, or iPad has been updated:<\/p>\n<p>* Navigate to Settings<br \/>* Select General<br \/>* Select About. The version after applying this update will be<br \/>&#8220;iOS 18.1.1 and iPadOS 18.1.1&#8221;.<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmc9JA8ACgkQX+5d1TXa<br \/>IvrGzw\/+PXf2fGgzCN5of6OYK0sWiJRRLZoL0uSZ9dOaD7I0\/CyAx91Mv4OyH9Vv<br \/>eo9k84ZABNk4IO401WWLM8XSRSVILTcskT+SdXZrtOMYvmtUHUPKI35OWf1GBFdk<br \/>gfnnFSRYf\/B+WWb4PV0iO01lyFQVU5qDLcrUCAUQLwighfAX2yEn+Zml3NX6i2E5<br \/>o2Rhc93Nac5a2cIcOGOSKrwsor0sh8NkAl9DcyPW6i6K3t59lUjiUY9XZQtEi6Ay<br \/>rChA84mo6Hb8wLwVIY17b8LVuruOSn3xg+Cc5eO5bOXp1O5lnR3dhuiZ2bl5BKaw<br \/>rp8+MDRsBZuTPS0k2Di3rmzuZ\/GnvaQdtQKhcbOQ7tWW6evk\/8TnFwlULaCr26OV<br \/>buLj0NWJ7GJYWpPuRWO0lFy9z9Fjdk4n+ptA7qmSWrhbdl+\/uwUxJA5X58pVRWeW<br \/>BExGP3S\/ST\/5YgAfZXBjHuDLiHKMOtQ3PktaMuEWhLFgGXNllXGQDihL4lS\/XUQ1<br \/>\/E+mpWyY+kAbjtmCYlpez5MgeLkVv66yEWhOhsBMNIM+jkkRjktJo2SfhJMSryNL<br \/>QlY37zn\/VWf8Av+L60YoZhoMmx7DJLIr+HI257zbIE35CVZ+badn18d3eA+fq3RP<br \/>tsDD8nlUePyZeNhEvc30Y5hXsIyK+Z0Ny+JgJfP1E6BeAJjjci0=<br \/>=ifwz<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1 iOS 18.1.1 and iPadOS 18.1.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121752. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. JavaScriptCoreAvailable for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch3rd generation &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60475","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60475"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60475\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}