First published: Mon Jul 09 2018(Updated: )
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
Credit: Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.6 | 7.6 |
Apple iTunes for Windows | <12.8 | 12.8 |
Apple Safari | <11.1.2 | 11.1.2 |
Apple tvOS | <11.4.1 | 11.4.1 |
Apple iOS | <11.4.1 | 11.4.1 |
Apple Safari | <11.1.2 | |
Apple iPhone OS | <11.4.1 | |
Apple tvOS | <11.4.1 | |
All of | ||
Any of | ||
Apple iCloud | <7.6 | |
Apple iTunes | <12.8 | |
Microsoft Windows | ||
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Apple iCloud | <7.6 | |
Apple iTunes | <12.8 | |
Microsoft Windows | ||
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.3-1~deb11u1 2.44.2-1~deb12u1 2.44.3-1~deb12u1 2.46.0-2 2.46.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2018-4278.
The severity of CVE-2018-4278 is medium.
Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6.
The CVE-2018-4278 vulnerability can be exploited by exfiltrating sound through audio elements across different origins.
The CVE-2018-4278 vulnerability was addressed with improved audio taint tracking.