First published: Thu Mar 29 2018(Updated: )
SafariViewController. A state management issue was addressed by disabling text input until the destination page loads.
Credit: Abhinash Jain @abhinashjain product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and iPadOS | <11.3 | 11.3 |
iPhone OS | <11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4149 is a vulnerability found in certain Apple products, specifically in the SafariViewController component on iOS before version 11.3.
CVE-2018-4149 has a severity rating of 8.8 (high).
CVE-2018-4149 affects iOS before version 11.3, allowing remote attackers to spoof the user interface via a crafted web site that leverages input into a partially loaded page.
To fix CVE-2018-4149, update your Apple device to iOS version 11.3 or later.
You can find more information about CVE-2018-4149 on the following references: [SecurityFocus](http://www.securityfocus.com/bid/103578), [SecurityTracker](http://www.securitytracker.com/id/1040604), and [Apple Support](https://support.apple.com/HT208693).