First published: Mon Jul 09 2018(Updated: )
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2.
Credit: product-security@apple.com Ruilin Yang Xu Taoyu (xia0yu.win) Jun Kokatsu @shhnjk
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <11.1.2 | 11.1.2 |
Apple Safari | <11.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4279 is a vulnerability in Safari that allows an attacker to manipulate the user interface and potentially perform unauthorized actions.
Versions of Safari prior to 11.1.2 are affected by CVE-2018-4279.
CVE-2018-4279 can be exploited by an attacker who tricks a user into visiting a malicious website and performing specific actions, which can lead to unauthorized actions being performed on behalf of the user.
CVE-2018-4279 has a severity score of 5.3, which is considered medium.
To fix CVE-2018-4279, update Safari to version 11.1.2 or later, which includes improvements to state management to address the vulnerability.