First published: Fri Jun 01 2018(Updated: )
Security. An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates.
Credit: Damian Poddebniak MChristian Dresen MJens Müller Ruhr University BochumFabian Ising MSebastian Schinzel MSimon Friedberger KU LeuvenJuraj Somorovsky Ruhr University BochumJörg Schwenk Ruhr University Bochum product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.4 | |
Apple Mac OS X | <10.13.5 | |
Apple macOS High Sierra | <10.13.5 | 10.13.5 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4221 is a vulnerability that affects certain Apple products including iOS before 11.4 and macOS before 10.13.5.
The severity of CVE-2018-4221 is rated as high with a CVSS score of 7.5.
CVE-2018-4221 allows web sites to track users by exploiting the transmission of S/MIME client certificates.
If you are using iOS before 11.4 or macOS before 10.13.5, you may be affected by CVE-2018-4221.
Yes, the issue has been addressed in iOS 11.4 and macOS 10.13.5. It is recommended to update to the latest version to fix the vulnerability.