First published: Fri Jun 08 2018(Updated: )
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app that replaces a privileged port name.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Apple Tv | <11.4 | |
Apple iPhone OS | <11.3.1 | |
Apple Mac OS X | <10.13.4 | |
Apple watchOS | <4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-4206.
The vulnerability affects certain Apple products, including Apple TV, iPhone OS, Mac OS X, and watchOS.
The severity rating for this vulnerability is high, with a value of 7.8.
Attackers can exploit this vulnerability by executing arbitrary code through the "Crash Reporter" component.
Yes, Apple has released security updates and patches to address this vulnerability. It is recommended to update to the latest available version of the affected software.