Apple Security Advisories · September 2018 — Apple Security Advisories
41 advisories 41 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2018-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4344

watchOSExploitedCISA KEV listedHIGH2018-09-25

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVEs:CVE-2018-4344

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4312

tvOSExploitedVulnCheck KEV listedCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4312

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4314

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4314

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4328

tvOSWeaponized exploitCRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4328

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4323

tvOSWeaponized exploitCRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4323

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4197

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4197

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4315

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4315

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4318

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4318

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4306

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4306

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4317

tvOSWeaponized exploitCRITICAL2018-09-25

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4317

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4330

iOSPoC exploitHIGH2018-09-18

In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.

CVEs:CVE-2018-4330

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4361

watchOSEPSS <= 49%HIGH2018-09-25

A memory consumption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4361

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4191

watchOSEPSS <= 49%CRITICAL2018-09-25

A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4191

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4359

watchOSEPSS <= 49%CRITICAL2018-09-25

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4359

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4299

watchOSEPSS <= 49%CRITICAL2018-09-24

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4299

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4358

watchOSEPSS <= 49%CRITICAL2018-09-24

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4358

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4316

tvOSEPSS <= 49%CRITICAL2018-09-25

A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4316

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4311

watchOSEPSS <= 49%HIGH2018-09-25

The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4311

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
watchos affected apple
Upstream advisory

CVE-2018-4309

tvOSEPSS <= 49%CRITICAL2018-09-24

A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4309

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4345

tvOSEPSS <= 49%CRITICAL2018-09-25

A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4345

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4338

macOSEPSS <= 49%MEDIUM2018-09-18

A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4338

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4321

tvOSEPSS <= 49%MEDIUM2018-09-25

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12.

CVEs:CVE-2018-4321

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2018-4353

macOSEPSS <= 49%CRITICAL2018-09-25

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4353

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4329

iOSEPSS <= 49%HIGH2018-09-18

Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12, Safari 12.

CVEs:CVE-2018-4329

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2018-4319

watchOSEPSS <= 49%HIGH2018-09-25

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVEs:CVE-2018-4319

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2018-4307

iOSEPSS <= 49%MEDIUM2018-09-18

A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.

CVEs:CVE-2018-4307

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2018-4336

watchOSEPSS <= 49%HIGH2018-09-25

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVEs:CVE-2018-4336

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4356

iOSEPSS <= 49%MEDIUM2018-09-18

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4356

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4362

iOSEPSS <= 49%MEDIUM2018-09-18

An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12.

CVEs:CVE-2018-4362

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2018-4195

SafariEPSS <= 49%MEDIUM2018-09-18

An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.

CVEs:CVE-2018-4195

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2018-4363

watchOSEPSS <= 49%HIGH2018-09-18

An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4363

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4357

XcodeEPSS <= 49%HIGH2018-09-18

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.

CVEs:CVE-2018-4357

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2018-4397

OtherEPSS <= 49%MEDIUM2018-09-18

Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.

CVEs:CVE-2018-4397

Affected products

ProductStatusVendorPackageEcosystem
apple_support affected apple
Upstream advisory

CVE-2018-4333

macOSEPSS <= 49%MEDIUM2018-09-25

A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

CVEs:CVE-2018-4333

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2018-4335

iOSEPSS <= 49%MEDIUM2018-09-18

A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4335

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4324

macOSEPSS <= 49%MEDIUM2018-09-25

A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions prior to macOS Mojave 10.14.

CVEs:CVE-2018-4324

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4305

watchOSEPSS <= 49%MEDIUM2018-09-17

An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4305

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4313

watchOSEPSS <= 49%MEDIUM2018-09-17

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

CVEs:CVE-2018-4313

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4325

iOSEPSS <= 49%LOW2018-09-18

A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4325

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4322

iOSEPSS <= 49%LOW2018-09-18

This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4322

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4352

iOSEPSS <= 49%LOW2018-09-18

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.

CVEs:CVE-2018-4352

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.