First published: Tue May 29 2018(Updated: )
CoreGraphics. An out-of-bounds read was addressed with improved input validation.
Credit: Jihui Lu Tencent KeenLabYu Zhou AntJihui Lu Tencent KeenLabYu Zhou Ant product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.7.5 | 12.7.5 |
Apple macOS High Sierra | <10.13.5 | 10.13.5 |
Apple Sierra | ||
Apple El Capitan | ||
Apple iPhone OS | <11.4 | |
Apple Mac OS X | >=10.13.0<10.13.5 | |
Apple watchOS | <4.3.1 | |
Apple iCloud | <7.5 | |
Apple iTunes | <12.7.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4194 is a vulnerability that allows an attacker to read data outside the specified bounds in various Apple software.
iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5 are affected by CVE-2018-4194.
CVE-2018-4194 has a severity rating of 8.8 (high).
To fix CVE-2018-4194, it is recommended to update to the latest version of the affected software provided by Apple.
You can find more information about CVE-2018-4194 on the official Apple support page: https://support.apple.com/en-us/HT208852