First published: Tue May 29 2018(Updated: )
CoreGraphics. An out-of-bounds read was addressed with improved input validation.
Credit: Jihui Lu Tencent KeenLabYu Zhou Ant product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS High Sierra | <10.13.5 | 10.13.5 |
macOS High Sierra | ||
Apple El Capitan | ||
iOS | <11.4 | |
Apple iOS and macOS | >=10.13.0<10.13.5 | |
Apple iOS, iPadOS, and watchOS | <4.3.1 | |
Apple iCloud for Windows | <7.5 | |
Apple iTunes for Windows | <12.7.5 | |
Microsoft Windows | ||
Apple iTunes | <12.7.5 | 12.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4194 is a vulnerability that allows an attacker to read data outside the specified bounds in various Apple software.
iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5 are affected by CVE-2018-4194.
CVE-2018-4194 has a severity rating of 8.8 (high).
To fix CVE-2018-4194, it is recommended to update to the latest version of the affected software provided by Apple.
You can find more information about CVE-2018-4194 on the official Apple support page: https://support.apple.com/en-us/HT208852