Apple Security Advisories · April 2018 — Apple Security Advisories
38 advisories 38 CVEs

Apple-vendor CVEs for 2018-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4200

tvOSWeaponized exploitCRITICAL2018-04-24

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves th...

CVEs:CVE-2018-4200

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-7005

tvOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to execute arbitrary code ...

CVEs:CVE-2017-7005

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4206

watchOSWeaponized exploitHIGH2018-04-24

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" compone...

CVEs:CVE-2018-4206

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4083

macOSWeaponized exploitHIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrup...

CVEs:CVE-2018-4083

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4204

tvOSWeaponized exploitCRITICAL2018-04-24

An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is af...

CVEs:CVE-2018-4204

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-7004

macOSWeaponized exploitHIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending X...

CVEs:CVE-2017-7004

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2017-13884

watchOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-13884

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7165

watchOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7165

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-13885

tvOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves th...

CVEs:CVE-2017-13885

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-7161

SafariWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection.

CVEs:CVE-2017-7161

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2017-7153

watchOSWeaponized exploitMEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7153

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7173

macOSPoC exploitMEDIUM2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVEs:CVE-2017-7173

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-2493

tvOSCoalition ESS 30-63%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attacker...

CVEs:CVE-2017-2493

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4148

iOSCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. A buffer overflow allows remote attackers to execute arbitrary code.

CVEs:CVE-2018-4148

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4187

macOSCoalition ESS < 30%MEDIUM2018-04-25

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to spoof the UI via a crafted U...

CVEs:CVE-2018-4187

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2017-7172

watchOSCoalition ESS < 30%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7172

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7002

macOSCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...

CVEs:CVE-2017-7002

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2017-7001

macOSCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...

CVEs:CVE-2017-7001

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2017-7167

XcodeCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.

CVEs:CVE-2017-7167

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2017-7071

SafariCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi...

CVEs:CVE-2017-7071

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2018-4109

watchOSCoalition ESS < 30%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows attackers to execute arbitrary code in a p...

CVEs:CVE-2018-4109

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple — —
iphone_os affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7171

watchOSCoalition ESS < 30%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CoreAnimation" component. It allows attackers to exe...

CVEs:CVE-2017-7171

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7170

macOSCoalition ESS < 30%HIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2017-7170

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-2492

tvOSCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) ...

CVEs:CVE-2017-2492

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-7003

watchOSCoalition ESS < 30%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attacker...

CVEs:CVE-2017-7003

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-7164

tvOSCoalition ESS < 30%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.

CVEs:CVE-2017-7164

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-6976

iOSCoalition ESS < 30%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to bypass intended access restrictions (for iCloud user records) via a crafted app.

CVEs:CVE-2017-6976

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4173

macOSCoalition ESS < 30%MEDIUM2018-04-13

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.

CVEs:CVE-2018-4173

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2017-7066

tvOSCoalition ESS < 30%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. tvOS before 10.2.2 is affected. The issue involves the "Wi-Fi" component. It allows attackers to cause a denial of service (memory corruption on the Wi-Fi chip) by levera...

CVEs:CVE-2017-7066

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2017-7070

macOSCoalition ESS < 30%MEDIUM2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows physically proximate attackers to bypass the screen-locking protection mechanism that should have been in place up...

CVEs:CVE-2017-7070

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-7075

iOSCoalition ESS < 30%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Notes" component. It allows local users to obtain sensitive information by reading search results that contain locked-note content.

CVEs:CVE-2017-7075

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2017-13904

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...

CVEs:CVE-2017-13904

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-13853

macOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory cor...

CVEs:CVE-2017-13853

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-13873

watchOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive n...

CVEs:CVE-2017-13873

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2017-13850

macOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Font Importer" component. It allows remote attackers to cause a denial of service (memory corruption) or obtain sensitive information from proc...

CVEs:CVE-2017-13850

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2017-13806

iOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Profiles" component. It does not enforce the configuration profile's settings for whether pairings are allowed.

CVEs:CVE-2017-13806

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2017-13877

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to determine whether arbitrary files exist via a crafted app.

CVEs:CVE-2017-13877

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2017-13863

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates.

CVEs:CVE-2017-13863

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.