Apple Security Advisories · April 2018 — Apple Security Advisories
38 advisories 38 CVEs 4 EXPLOITED

Apple-vendor CVEs for 2018-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-7005

tvOSExploitedCISA KEV listedCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to execute arbitrary code ...

CVEs:CVE-2017-7005

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4206

watchOSExploitedCISA KEV listedHIGH2018-04-24

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" compone...

CVEs:CVE-2018-4206

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4083

macOSExploitedCISA KEV listedHIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrup...

CVEs:CVE-2018-4083

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-7004

macOSExploitedCISA KEV listedHIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending X...

CVEs:CVE-2017-7004

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2018-4200

tvOSWeaponized exploitCRITICAL2018-04-24

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves th...

CVEs:CVE-2018-4200

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4204

tvOSWeaponized exploitCRITICAL2018-04-24

An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is af...

CVEs:CVE-2018-4204

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2017-13884

watchOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-13884

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-7165

watchOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7165

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-13885

tvOSWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves th...

CVEs:CVE-2017-13885

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2017-7161

SafariWeaponized exploitCRITICAL2018-04-03

An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection.

CVEs:CVE-2017-7161

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2017-7153

watchOSWeaponized exploitMEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7153

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-7173

macOSPoC exploitMEDIUM2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVEs:CVE-2017-7173

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4148

iOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. A buffer overflow allows remote attackers to execute arbitrary code.

CVEs:CVE-2018-4148

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4187

macOSEPSS <= 49%MEDIUM2018-04-25

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to spoof the UI via a crafted U...

CVEs:CVE-2018-4187

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2017-7172

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is...

CVEs:CVE-2017-7172

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-7002

macOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...

CVEs:CVE-2017-7002

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2017-7001

macOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...

CVEs:CVE-2017-7001

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2017-2493

tvOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attacker...

CVEs:CVE-2017-2493

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2017-13904

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute ar...

CVEs:CVE-2017-13904

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-7167

XcodeEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.

CVEs:CVE-2017-7167

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2017-7071

SafariEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi...

CVEs:CVE-2017-7071

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2018-4109

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows attackers to execute arbitrary code in a p...

CVEs:CVE-2018-4109

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2017-7171

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CoreAnimation" component. It allows attackers to exe...

CVEs:CVE-2017-7171

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-7170

macOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVEs:CVE-2017-7170

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-13853

macOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory cor...

CVEs:CVE-2017-13853

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-2492

tvOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) ...

CVEs:CVE-2017-2492

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2017-7003

watchOSEPSS <= 49%HIGH2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attacker...

CVEs:CVE-2017-7003

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-13873

watchOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive n...

CVEs:CVE-2017-13873

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2017-13850

macOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Font Importer" component. It allows remote attackers to cause a denial of service (memory corruption) or obtain sensitive information from proc...

CVEs:CVE-2017-13850

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-7164

tvOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.

CVEs:CVE-2017-7164

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2017-6976

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to bypass intended access restrictions (for iCloud user records) via a crafted app.

CVEs:CVE-2017-6976

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4173

macOSEPSS <= 49%MEDIUM2018-04-13

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.

CVEs:CVE-2018-4173

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2017-13806

iOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Profiles" component. It does not enforce the configuration profile's settings for whether pairings are allowed.

CVEs:CVE-2017-13806

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-13877

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to determine whether arbitrary files exist via a crafted app.

CVEs:CVE-2017-13877

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-7066

tvOSEPSS <= 49%CRITICAL2018-04-03

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. tvOS before 10.2.2 is affected. The issue involves the "Wi-Fi" component. It allows attackers to cause a denial of service (memory corruption on the Wi-Fi chip) by levera...

CVEs:CVE-2017-7066

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2017-13863

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates.

CVEs:CVE-2017-13863

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-7070

macOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows physically proximate attackers to bypass the screen-locking protection mechanism that should have been in place up...

CVEs:CVE-2017-7070

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-7075

iOSEPSS <= 49%MEDIUM2018-04-03

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Notes" component. It allows local users to obtain sensitive information by reading search results that contain locked-note content.

CVEs:CVE-2017-7075

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.