First published: Wed Sep 12 2018(Updated: )
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Credit: Ivan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project Zero product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.7 | 7.7 |
Apple iTunes for Windows | <12.9 | 12.9 |
Apple Safari | <12 | 12 |
Apple tvOS | <12 | 12 |
Apple iOS | <12 | 12 |
Apple Safari | <12 | |
Apple iPhone OS | <12.0 | |
Apple tvOS | <12 | |
All of | ||
Any of | ||
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4312 is a use after free vulnerability in WebKit that has been fixed with improved memory management.
Versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, and iCloud for Windows 7.7 are affected by CVE-2018-4312.
CVE-2018-4312 has a severity rating of 8.8 (high).
To fix CVE-2018-4312, update to the latest version of iOS, tvOS, Safari, iTunes for Windows, or iCloud for Windows, as provided by the vendors.
More information about CVE-2018-4312 can be found at the following references: [Link 1](https://support.apple.com/kb/HT209106), [Link 2](https://support.apple.com/kb/HT209107), [Link 3](https://support.apple.com/kb/HT209109).