First published: Tue Oct 30 2018(Updated: )
WebKit. A resource exhaustion issue was addressed with improved input validation.
Credit: Sabri Haddouche @pwnsdx Wire Swiss GmbHSabri Haddouche @pwnsdx Wire Swiss GmbHSabri Haddouche @pwnsdx Wire Swiss GmbHSabri Haddouche @pwnsdx Wire Swiss GmbHSabri Haddouche @pwnsdx Wire Swiss GmbH product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.8 | 7.8 |
Apple iTunes for Windows | <12.9.1 | 12.9.1 |
Apple Safari | <12.0.1 | 12.0.1 |
Apple tvOS | <12.1 | 12.1 |
Apple iOS | <12.1 | 12.1 |
Apple Safari | <12.0.1 | |
Apple iPhone OS | <12.1 | |
Apple tvOS | <12.1 | |
Apple iCloud | <7.8 | |
Apple iTunes | <12.9.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4409 is a vulnerability in WebKit that allows for a resource exhaustion issue due to improved input validation.
Versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, and iCloud for Windows 7.8 are affected by CVE-2018-4409.
CVE-2018-4409 has a severity value of 6.5, indicating a medium severity.
To fix CVE-2018-4409, update your software to iOS 12.1 or later, tvOS 12.1 or later, Safari 12.0.1 or later, iTunes 12.9.1 or later, or iCloud for Windows 7.8 or later.
You can find more information about CVE-2018-4409 on the Apple support website at the following links: [Link 1](https://support.apple.com/kb/HT209192), [Link 2](https://support.apple.com/kb/HT209194), [Link 3](https://support.apple.com/kb/HT209196).