First published: Mon Sep 17 2018(Updated: )
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
Credit: product-security@apple.com Yiğit Can YILMAZ @yilmazcanyigit
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Support | <2.4 | 2.4 |
Apple Support | <2.4 | |
iStyle @cosme iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-4397 is considered moderate due to potential exposure of sensitive analytics data.
To fix CVE-2018-4397, upgrade to Apple Support version 2.4 or later.
Versions of Apple Support prior to 2.4 for iOS are vulnerable to CVE-2018-4397.
CVE-2018-4397 does not affect the iPhone OS itself, but rather the Apple Support app for iOS.
CVE-2018-4397 affected analytics data which was sent over HTTP instead of HTTPS.