First published: Fri Jun 01 2018(Updated: )
Messages. An injection issue was addressed with improved input validation.
Credit: Anurodh Pokharel Salesforce product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS High Sierra | <10.13.5 | 10.13.5 |
macOS High Sierra | ||
Apple El Capitan | ||
Apple TV | <11.4 | |
iOS | <11.4 | |
Apple iOS and macOS | <10.13.5 | |
Apple iOS, iPadOS, and watchOS | <4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4235 is a vulnerability that allows local users to perform impersonation attacks via an unspecified injection in the Messages component of certain Apple products.
iOS before 11.4, macOS before 10.13.5, tvOS before 11.4, and watchOS before 4.3.1 are affected by CVE-2018-4235.
CVE-2018-4235 has a severity score of 5.5 out of 10.
To fix CVE-2018-4235, update your Apple device to the latest available software version.
You can find more information about CVE-2018-4235 on the SecurityTracker website and Apple support pages.