Apple Security Advisories · September 2018 — Apple Security Advisories
41 advisories 41 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2018-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4344

watchOSExploitedCISA KEV listedHIGH2018-09-25

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVEs:CVE-2018-4344

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4312

tvOSExploitedVulnCheck KEV listedCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4312

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4314

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4314

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4328

tvOSWeaponized exploitCRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4328

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4323

tvOSWeaponized exploitCRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4323

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4197

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4197

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4315

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4315

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4318

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4318

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4306

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4306

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4317

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4317

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4330

iOSPoC exploitHIGH2018-09-18

In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.

CVEs:CVE-2018-4330

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4359

watchOSCoalition ESS < 30%CRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4359

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4361

watchOSCoalition ESS < 30%HIGH2018-09-25

A memory consumption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4361

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4191

watchOSCoalition ESS < 30%CRITICAL2018-09-25

A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4191

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4299

watchOSCoalition ESS < 30%CRITICAL2018-09-24

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4299

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4358

watchOSCoalition ESS < 30%CRITICAL2018-09-24

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4358

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4316

tvOSCoalition ESS < 30%CRITICAL2018-09-25

A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4316

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4311

watchOSCoalition ESS < 30%HIGH2018-09-25

The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4311

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4309

tvOSCoalition ESS < 30%CRITICAL2018-09-24

A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4309

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4345

tvOSCoalition ESS < 30%CRITICAL2018-09-25

A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4345

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4338

macOSCoalition ESS < 30%MEDIUM2018-09-18

A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4338

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4321

tvOSCoalition ESS < 30%MEDIUM2018-09-25

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.

CVEs:CVE-2018-4321

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2018-4353

macOSCoalition ESS < 30%CRITICAL2018-09-25

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4353

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4329

iOSCoalition ESS < 30%HIGH2018-09-18

Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12, Safari 12.

CVEs:CVE-2018-4329

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4319

watchOSCoalition ESS < 30%HIGH2018-09-25

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4319

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4307

iOSCoalition ESS < 30%MEDIUM2018-09-18

A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.

CVEs:CVE-2018-4307

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4336

watchOSCoalition ESS < 30%HIGH2018-09-25

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVEs:CVE-2018-4336

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4356

iOSCoalition ESS < 30%MEDIUM2018-09-18

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4356

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4362

iOSCoalition ESS < 30%MEDIUM2018-09-18

An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12.

CVEs:CVE-2018-4362

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4195

SafariCoalition ESS < 30%MEDIUM2018-09-18

An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.

CVEs:CVE-2018-4195

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2018-4363

watchOSCoalition ESS < 30%HIGH2018-09-18

An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4363

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4357

XcodeCoalition ESS < 30%HIGH2018-09-18

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.

CVEs:CVE-2018-4357

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2018-4397

OtherCoalition ESS < 30%MEDIUM2018-09-18

Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.

CVEs:CVE-2018-4397

Affected products

ProductStatusVendorPackageEcosystem
apple_support affected apple — —
Upstream advisory

CVE-2018-4333

macOSCoalition ESS < 30%MEDIUM2018-09-25

A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

CVEs:CVE-2018-4333

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4335

iOSCoalition ESS < 30%MEDIUM2018-09-18

A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4335

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4324

macOSCoalition ESS < 30%MEDIUM2018-09-25

A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4324

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4305

watchOSCoalition ESS < 30%MEDIUM2018-09-17

An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4305

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4313

watchOSCoalition ESS < 30%MEDIUM2018-09-17

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4313

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4325

iOSCoalition ESS < 30%LOW2018-09-18

A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4325

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4322

iOSCoalition ESS < 30%LOW2018-09-18

This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4322

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4352

iOSCoalition ESS < 30%LOW2018-09-18

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4352

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.