About the security content of Safari 18.1 – Apple Support

About the security content of Safari 18.1 - Apple Support

October 29, 2024 at 02:42PM

Apple released updates for Safari 18.1 on macOS Ventura and Sonoma on October 28, 2024, addressing multiple vulnerabilities (CVE-2024-44259, CVE-2024-44244, CVE-2024-44229, CVE-2024-44296). Issues included memory corruption and failures to enforce Content Security Policy, potentially causing process crashes when processing malicious web content.

**Meeting Notes Takeaways:**

**Release Information:**
– **Apple ID:** 121571
– **Release Date:** October 28, 2024

**Security Updates for Safari 18.1 (macOS Ventura and macOS Sonoma):**

1. **CVE-2024-44259**
– **Description:** Addressed a memory corruption issue with improved input validation.
– **Impact:** May lead to unexpected process crashes when processing maliciously crafted web content.

2. **CVE-2024-44244**
– **Description:** Addressed a memory corruption issue with improved input validation.
– **Impact:** May lead to unexpected process crashes when processing maliciously crafted web content.

3. **CVE-2024-44229 / CVE-2024-44296** (These CVEs seem to address similar issues)
– **Description:** Addressed with improved checks.
– **Impact:** May prevent Content Security Policy from being enforced when processing maliciously crafted web content.

**Summary of Affected Product:**
– Security content relevant to **Safari 18.1** is affected by the issues listed above and updates are available for **macOS Ventura** and **macOS Sonoma**.

Full Article