Remote Code Execution Vulnerability in Apple WebKit across Multiple Products
CVE-2018-4089

8.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
3 April 2018

Summary

A vulnerability exists in Apple's WebKit component that affects various products, allowing remote attackers to execute arbitrary code. This issue can be triggered through a specially crafted website, potentially leading to memory corruption or application crashes. The vulnerability impacts iOS, macOS, and Safari, necessitating prompt action for users to protect their devices from exploitation.

References

EPSS Score

52% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.