First published: Thu Mar 29 2018(Updated: )
Telephony. A null pointer dereference issue existed when handling Class 0 SMS messages. This issue was addressed with improved message validation.
Credit: @mjonsson Arjan van der Oest Voiceworks BV product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
iStyle @cosme iPhone OS | <11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4140 is a null pointer dereference vulnerability in certain Apple products, specifically iOS before 11.3.
CVE-2018-4140 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a Class 0 SMS message.
CVE-2018-4140 has a severity rating of 7.5 (high).
To fix CVE-2018-4140, update your iOS version to 11.3 or newer.
You can find more information about CVE-2018-4140 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/103578), [SecurityTracker](http://www.securitytracker.com/id/1040604), and [Apple Support](https://support.apple.com/HT208693)