Local Access Vulnerability in Apple iOS, macOS, tvOS, and watchOS Products
CVE-2018-4223
5.5MEDIUM
Summary
A vulnerability in several Apple products allows local users to circumvent intended restrictions, enabling unauthorized access to a persistent account identifier. This affects various Apple operating systems, including iOS 11.4, macOS 10.13.5, tvOS 11.4, and watchOS 4.3.1 and earlier versions. Users should ensure their devices are updated to the latest versions to mitigate this risk.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved