First published: Mon Sep 17 2018(Updated: )
IOKit. A memory corruption issue was addressed with improved memory handling.
Credit: Ian Beer Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <12 | 12 |
macOS Mojave | <10.14.1 | 10.14.1 |
macOS High Sierra | ||
macOS High Sierra | ||
macOS Mojave | <10.14 | 10.14 |
Apple iOS, iPadOS, and watchOS | <5 | 5 |
Apple iOS and iPadOS | <12 | 12 |
iPhone OS | <12.0 | |
Apple iOS and macOS | <10.14 | |
tvOS | <12 | |
Apple iOS, iPadOS, and watchOS | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4354 is a vulnerability in IOKit that allows an attacker to execute arbitrary code with kernel privileges.
Versions of macOS Mojave prior to 10.14.1 are affected by CVE-2018-4354.
Versions of iOS prior to 12.0 are affected by CVE-2018-4354.
Yes, updating to macOS Mojave 10.14.1 or later, iOS 12.0 or later, tvOS 12.0 or later, or watchOS 5.0 or later will address the vulnerability.
CVE-2018-4354 has a severity rating of 8.6 (High).