Arbitrary Code Execution and Denial of Service in Apple Products
CVE-2018-4206

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
8 June 2018

Summary

The vulnerability arises in the Crash Reporter component of various Apple platforms including iOS, macOS, tvOS, and watchOS. Attackers can exploit this vulnerability by using a specially crafted application to replace a privileged port name, which may lead to arbitrary code execution or cause a denial of service through memory corruption. It is crucial for users to update their systems to the latest versions to mitigate potential risks associated with this security flaw.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.