First published: Mon Jul 09 2018(Updated: )
Last updated 24 July 2024
Credit: Omair Trend MicroMateusz Krzywicki Trend MicroArayz Trend Microfound by OSS-Fuzz Yu Zhou Jundong Xie Antcc Trend MicroArayz Pangu team working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.3-1~deb11u1 2.44.2-1~deb12u1 2.44.3-1~deb12u1 2.46.0-2 2.46.1-1 | |
tvOS | <11.4.1 | 11.4.1 |
Apple Mobile Safari | <11.1.2 | 11.1.2 |
Apple iOS, iPadOS, and watchOS | <11.4.1 | 11.4.1 |
Apple iOS, iPadOS, and watchOS | <4.3.2 | 4.3.2 |
Apple iCloud | <7.6 | 7.6 |
Apple iTunes | <12.8 | 12.8 |
Apple Mobile Safari | <11.1.2 | |
iStyle @cosme iPhone OS | <11.4.1 | |
tvOS | <11.4.1 | |
Apple iOS, iPadOS, and watchOS | <4.3.2 | |
All of | ||
Any of | ||
Apple iCloud for Windows | <7.6 | |
Apple iTunes for Windows | <12.8 | |
Microsoft Windows | ||
Apple iCloud for Windows | <7.6 | |
Apple iTunes for Windows | <12.8 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4264 is a vulnerability in WebKit that allows memory corruption.
Versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, and iCloud for Windows 7.6 are affected by CVE-2018-4264.
CVE-2018-4264 has a severity value of 8.8, which is considered high.
To fix CVE-2018-4264 on Ubuntu, update the webkit2gtk package to version 2.20.5-0ubuntu0.18.04.1.
To fix CVE-2018-4264 on Apple devices, update to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, and iCloud for Windows 7.6.