First published: Tue Apr 03 2018(Updated: )
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Apple Tv | <11.2.5 | |
Apple iPhone OS | <11.2.5 | |
Apple Mac OS X | <10.13.3 | |
Apple watchOS | <4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-4090 is medium with a severity value of 5.5.
Certain Apple products including iOS, macOS, tvOS, and watchOS are affected by CVE-2018-4090.
Attackers can bypass intended memory-read restrictions via a crafted exploit for CVE-2018-4090.
To protect your Apple products, update them to the latest versions of iOS (11.2.5 or later), macOS (10.13.3 or later), tvOS (11.2.5 or later), and watchOS (4.2.2 or later).
You can find more information about CVE-2018-4090 on security websites such as SecurityFocus and SecurityTracker.