First published: Thu Mar 29 2018(Updated: )
LaunchServices. A logic issue was addressed with improved validation.
Credit: Theodor Ragnar Gislason Syndis product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS High Sierra | <10.13.4 | 10.13.4 |
Apple Sierra | ||
Apple El Capitan | ||
Apple Mac OS X | <10.13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2018-4175.
macOS High Sierra before version 10.13.4, Sierra, and El Capitan are affected by this vulnerability.
The severity of CVE-2018-4175 is high with a CVSS score of 7.8.
Attackers can exploit this vulnerability by bypassing the code-signing protection mechanism via a crafted app.
Yes, the fix for this vulnerability is available in macOS version 10.13.4 and above.