First published: Thu Mar 29 2018(Updated: )
CoreFoundation. A race condition was addressed with additional validation.
Credit: Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.3 | |
Apple Mac OS X | <10.13.4 | |
Apple watchOS | <4.3 | |
Apple watchOS | <4.3 | 4.3 |
Apple iOS | <11.3 | 11.3 |
Apple macOS High Sierra | <10.13.4 | 10.13.4 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2018-4158.
The severity of CVE-2018-4158 is high.
macOS High Sierra before 10.13.4, iOS before 11.3, and watchOS before 4.3 are affected by CVE-2018-4158.
An attacker can exploit CVE-2018-4158 by executing arbitrary code in a privileged context via a crafted app.
You can find more information about CVE-2018-4158 on the Apple support website.