First published: Wed Dec 05 2018(Updated: )
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Credit: lokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Teamlokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Teamlokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Teamlokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Teamlokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Teamlokihardt Google Project ZeroQixun Zhao Qihoo 360 Vulcan Team product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.9 | 7.9 |
Apple iTunes for Windows | <12.9.2 | 12.9.2 |
Apple Safari | <12.0.2 | 12.0.2 |
Apple watchOS | <5.1.2 | 5.1.2 |
Apple tvOS | <12.1.1 | 12.1.1 |
Apple iOS | <12.1.1 | 12.1.1 |
Apple Safari | <12.0.2 | |
Apple iPhone OS | <12.1.1 | |
Apple tvOS | <12.1.1 | |
Apple watchOS | <5.1.2 | |
Apple iCloud | <7.9 | |
Apple iTunes | <12.9.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4438 is a vulnerability in WebKit that resulted in memory corruption and was addressed with improved state management.
CVE-2018-4438 affects versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, and iCloud for Windows 7.9.
CVE-2018-4438 has a severity score of 8.8 (high).
To fix CVE-2018-4438, you should update your software to iOS 12.1.1 or later, tvOS 12.1.1 or later, watchOS 5.1.2 or later, Safari 12.0.2 or later, iTunes 12.9.2 for Windows or later, and iCloud for Windows 7.9 or later.
You can find more information about CVE-2018-4438 on the Apple support page: [link](https://support.apple.com/kb/HT209340).