{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-44308",
  "revision": 1,
  "title": "Apple WebKit — crafted web content runs code",
  "summary": "Safari 18.1.1 and the matching iOS, iPadOS, macOS and visionOS releases run the attacker's code when processing crafted web content. Apple gives no detail, and no weakness class is recorded.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.10157,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-11-21",
    "prerequisites": "The user must open attacker-controlled web content in an affected browser."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Safari 18.1.1",
      "iOS 17.7.2",
      "iPadOS 17.7.2",
      "iOS 18.1.1",
      "iPadOS 18.1.1",
      "macOS Sequoia 15.1.1",
      "visionOS 2.1.1"
    ]
  },
  "kill_chain": "execution",
  "recommended_action": "Update to Safari 18.1.1, iOS and iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 or visionOS 2.1.1 now; it pairs with a script injection flaw.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-44308",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-44308",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-44308",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44308",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/121752"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/121753"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/121754"
    }
  ],
  "published_at": "2024-11-20T00:15:17.080Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "apple",
    "webkit",
    "safari",
    "remote-code-execution",
    "kev"
  ]
}
