First published: Wed Sep 12 2018(Updated: )
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Credit: Ivan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project ZeroIvan Fratric Google Project Zero product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.7 | 7.7 |
Apple iTunes for Windows | <12.9 | 12.9 |
Apple Safari | <12 | 12 |
Apple tvOS | <12 | 12 |
Apple iOS | <12 | 12 |
Apple Safari | <12 | |
Apple iPhone OS | <12.0 | |
Apple tvOS | <12 | |
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
All of | ||
Any of | ||
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4314 is a use after free vulnerability in WebKit that has been fixed with improved memory management.
Versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, and iCloud for Windows 7.7 are affected by CVE-2018-4314.
CVE-2018-4314 has a severity score of 8.8 (high).
To fix CVE-2018-4314, ensure that you update to iOS 12 (or later), tvOS 12 (or later), Safari 12 (or later), iTunes 12.9 (or later) for Windows, and iCloud for Windows 7.7 (or later).
You can find more information about CVE-2018-4314 and its fixes on the Apple support page: [HT209106](https://support.apple.com/kb/HT209106), [HT209107](https://support.apple.com/kb/HT209107), [HT209109](https://support.apple.com/kb/HT209109).