First published: Tue Apr 03 2018(Updated: )
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. tvOS before 11.2.5 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Apple Tv | <11.2.5 | |
Apple Safari | <11.0.3 | |
Apple iPhone OS | <11.2.5 | |
Apple Mac OS X | <10.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4089 is a vulnerability found in certain Apple products that allows remote attackers to execute arbitrary code or cause a denial of service.
CVE-2018-4089 affects iOS versions before 11.2.5, macOS versions before 10.13.3, Safari versions before 11.0.3, and Apple TV versions before 11.2.5.
CVE-2018-4089 has a severity rating of 8.8 (high).
CVE-2018-4089 can be exploited by remote attackers to execute arbitrary code or cause a denial of service.
To mitigate CVE-2018-4089, update your Apple devices to the latest iOS, macOS, Safari, or Apple TV versions.