Apple Security Advisories · January 2018 — Apple Security Advisories
17 advisories 17 CVEs 3 EXPLOITED

Apple-vendor CVEs for 2018-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4087

watchOSExploitedCISA KEV listedHIGH2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Core Bluetooth" component. It allows attackers to execute arbitrary code in a pr...

CVEs:CVE-2018-4087

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2018-4089

tvOSExploitedCISA KEV listedCRITICAL2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. tvOS before 11.2.5 is affected. The issue involves the "WebKit" component. It allows remote attackers ...

CVEs:CVE-2018-4089

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2018-4090

watchOSExploitedCISA KEV listedMEDIUM2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypa...

CVEs:CVE-2018-4090

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4088

tvOSWeaponized exploitCRITICAL2018-01-23

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11....

CVEs:CVE-2018-4088

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
icloud affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
watchos affected apple
Upstream advisory

CVE-2018-4096

tvOSWeaponized exploitCRITICAL2018-01-23

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11....

CVEs:CVE-2018-4096

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
icloud affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
watchos affected apple
Upstream advisory

CVE-2018-4084

macOSPoC exploitMEDIUM2018-01-24

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVEs:CVE-2018-4084

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4100

watchOSEPSS <= 49%CRITICAL2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of s...

CVEs:CVE-2018-4100

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4095

watchOSEPSS <= 49%HIGH2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Core Bluetooth" component. It allows attackers to execute arbitrary code in a pr...

CVEs:CVE-2018-4095

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2018-4091

macOSEPSS <= 49%CRITICAL2018-01-24

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism.

CVEs:CVE-2018-4091

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4097

macOSEPSS <= 49%HIGH2018-01-24

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2018-4097

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4094

watchOSEPSS <= 49%CRITICAL2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Audio" component. It allows remote attackers t...

CVEs:CVE-2018-4094

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4085

watchOSEPSS <= 49%CRITICAL2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "QuartzCore" component. It allows remote attack...

CVEs:CVE-2018-4085

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4082

watchOSEPSS <= 49%HIGH2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to exec...

CVEs:CVE-2018-4082

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4098

macOSEPSS <= 49%HIGH2018-01-24

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) ...

CVEs:CVE-2018-4098

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4093

watchOSEPSS <= 49%MEDIUM2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypa...

CVEs:CVE-2018-4093

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4086

watchOSEPSS <= 49%MEDIUM2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Security" component. It allows remote attacker...

CVEs:CVE-2018-4086

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4092

watchOSEPSS <= 49%MEDIUM2018-01-24

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. A race condition allows att...

CVEs:CVE-2018-4092

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.