First published: Wed Dec 05 2018(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
Credit: James Lee @Windowsrcer S2SWWWJames Lee @Windowsrcer S2SWWWJames Lee @Windowsrcer S2SWWWJames Lee @Windowsrcer S2SWWW product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.9.2 | 12.9.2 |
Apple Safari | <12.0.2 | 12.0.2 |
Apple tvOS | <12.1.1 | 12.1.1 |
Apple iOS | <12.1.1 | 12.1.1 |
Apple Itunes Windows | <12.9.2 | |
Apple Safari | <12.0.2 | |
Apple iPhone OS | <12.1.1 | |
Apple tvOS | <12.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4444 is a vulnerability in WebKit that allows processing maliciously crafted web content to disclose sensitive user information.
The severity of CVE-2018-4444 is medium with a CVSS score of 6.5.
The affected Apple products are Safari (up to version 12.0.2), iOS (up to version 12.1.1), tvOS (up to version 12.1.1), and iTunes for Windows (up to version 12.9.2).
To fix CVE-2018-4444, update Safari to version 12.0.2, iOS to version 12.1.1, tvOS to version 12.1.1, and iTunes for Windows to version 12.9.2.
You can find more information about CVE-2018-4444 on the Apple security support website at the following links: [link1](https://support.apple.com/en-us/HT209342), [link2](https://support.apple.com/en-us/HT209340), [link3](https://support.apple.com/en-us/HT209344).