Apple Security Advisories · December 2018 — Apple Security Advisories
27 advisories 27 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2018-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-4443

watchOSExploitedVulnCheck KEV listedCRITICAL2018-12-05

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4443

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4441

watchOSWeaponized exploitCRITICAL2018-12-05

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4441

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4438

watchOSWeaponized exploitCRITICAL2018-12-06

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4438

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4442

watchOSWeaponized exploitCRITICAL2018-12-06

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4442

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4435

watchOSWeaponized exploitHIGH2018-12-06

A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4435

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4463

macOSWeaponized exploitHIGH2018-12-06

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

CVEs:CVE-2018-4463

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-20506

OtherActive exploitation (sightings)CRITICAL2018-12-21

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execu...

CVEs:CVE-2018-20506

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-20505

OtherActive exploitation (sightings)CRITICAL2018-12-21

SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

CVEs:CVE-2018-20505

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4431

watchOSPoC exploitMEDIUM2018-12-06

A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4431

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4439

iOSCoalition ESS < 30%MEDIUM2018-12-06

A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4439

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4440

iOSCoalition ESS < 30%MEDIUM2018-12-06

A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4440

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4460

watchOSCoalition ESS < 30%HIGH2018-12-06

A denial of service issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4460

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4437

watchOSCoalition ESS < 30%CRITICAL2018-12-06

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4437

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4464

watchOSCoalition ESS < 30%CRITICAL2018-12-06

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

CVEs:CVE-2018-4464

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4447

watchOSCoalition ESS < 30%HIGH2018-12-06

A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4447

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4461

watchOSCoalition ESS < 30%HIGH2018-12-06

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4461

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4449

macOSCoalition ESS < 30%HIGH2018-12-06

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

CVEs:CVE-2018-4449

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4303

watchOSCoalition ESS < 30%HIGH2018-12-06

An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14, iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4303

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4436

watchOSCoalition ESS < 30%HIGH2018-12-06

A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4436

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4450

macOSCoalition ESS < 30%HIGH2018-12-06

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

CVEs:CVE-2018-4450

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4429

watchOSCoalition ESS < 30%MEDIUM2018-12-06

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4429

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2018-4465

watchOSCoalition ESS < 30%HIGH2018-12-06

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

CVEs:CVE-2018-4465

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4462

macOSCoalition ESS < 30%MEDIUM2018-12-06

A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2.

CVEs:CVE-2018-4462

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4446

iOSCoalition ESS < 30%MEDIUM2018-12-06

This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.

CVEs:CVE-2018-4446

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2018-4445

iOSCoalition ESS < 30%MEDIUM2018-12-06

"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2.

CVEs:CVE-2018-4445

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2018-4434

macOSCoalition ESS < 30%HIGH2018-12-06

An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.2.

CVEs:CVE-2018-4434

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2018-4430

iOSCoalition ESS < 30%LOW2018-12-06

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1.

CVEs:CVE-2018-4430

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.