First published: Tue Apr 03 2018(Updated: )
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to bypass intended memory-read restrictions via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Apple Tv | <11.2.5 | |
Apple iPhone OS | <11.2.5 | |
Apple Mac OS X | <10.13.3 | |
Apple watchOS | <4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4092 is a vulnerability in certain Apple products that allows attackers to bypass memory-read restrictions.
iOS before 11.2.5, macOS before 10.13.3, tvOS before 11.2.5, and watchOS before 4.2.2 are affected by CVE-2018-4092.
CVE-2018-4092 has a severity level of medium (4.7).
To fix CVE-2018-4092, update your iOS to version 11.2.5 or later, macOS to version 10.13.3 or later, tvOS to version 11.2.5 or later, and watchOS to version 4.2.2 or later.
You can find more information about CVE-2018-4092 at the following URLs: [securityfocus](http://www.securityfocus.com/bid/102782), [securitytracker 1](http://www.securitytracker.com/id/1040265), [securitytracker 2](http://www.securitytracker.com/id/1040267).