CERT-In Issues Critical Security Alert for Apple Users: Update Your Devices Now
Apple users face a critical security threat, as highlighted in an urgent advisory from the Computer Emergency Response Team (CERT-In). Issued on November 21, 2024, the alert warns of severe vulnerabilities affecting Macs, iPhones, iPads, and Safari browsers, which could expose devices to cyberattacks. CERT-In has urged users to update their devices immediately to safeguard against potential breaches.
Identified Vulnerabilities
The advisory points to two major vulnerabilities:
Execution Vulnerability (CVE-2024-44308):
Found in Safari’s JavaScriptCore component, this flaw allows attackers to inject malicious web content, potentially executing arbitrary code on affected devices.
Cross-Site Scripting (XSS) Vulnerability (CVE-2024-44309):
This vulnerability is located in WebKit, Safari’s engine, enabling attackers to exploit user sessions or steal sensitive information via harmful scripts.
These flaws make devices vulnerable to unauthorized access, data manipulation, and malicious activities.
Devices at Risk
The vulnerabilities affect Apple devices running Intel-based systems, including macOS, iOS, and iPadOS. Attackers can exploit these issues to compromise personal data or even take control of affected systems.
How to Protect Your Device
- To mitigate these risks, CERT-In recommends these updates:
- iPhones and iPads: Upgrade to iOS 18.1.1 or iOS 17.7.2, depending on your model.
- Macs: Update to macOS Sequoia 15.1.1.
- Apple visionOS: Install version 2.1.1.
- Safari browser: Upgrade to version 18.1.1.
- Staying updated with these patches is crucial to protecting your device from evolving cyber threats.
Stay Alert
Cybercriminals are constantly finding ways to exploit vulnerabilities, making regular updates essential for security. Apple users should prioritize these upgrades to prevent unauthorized access, data theft, or control of their devices. By maintaining updated software, you can ensure your personal information remains safe in an increasingly digital world.