First published: Thu Mar 29 2018(Updated: )
CoreFoundation. A race condition was addressed with additional validation.
Credit: Samuel Groß @5aelo product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS High Sierra | <10.13.4 | 10.13.4 |
macOS High Sierra | ||
Apple El Capitan | ||
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
Apple iOS, iPadOS, and watchOS | <4.3 | 4.3 |
iOS | <11.3 | |
Apple iOS and macOS | <10.13.4 | |
Apple iOS, iPadOS, and watchOS | <4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2018-4158.
The severity of CVE-2018-4158 is high.
macOS High Sierra before 10.13.4, iOS before 11.3, and watchOS before 4.3 are affected by CVE-2018-4158.
An attacker can exploit CVE-2018-4158 by executing arbitrary code in a privileged context via a crafted app.
You can find more information about CVE-2018-4158 on the Apple support website.