VDB
CVE-2018-4206
CVE-2018-4206
PUBLISHED
CVSS 7.800000190734863 HIGH
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app that replaces a privileged port name.
EPSS 7.65% · 92.0th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
7.65%
92.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | iphone_os | 0 |
| n/a | n/a | n/a |
| apple | watchos | 0 |
| apple | mac_os_x | 0 |
| apple | apple_tv | 0 |
Exploit Intelligence
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1529 (nist-nvd)
- https://www.exploit-db.com/exploits/44562/ (nist-nvd)
- CIRCL exploited: CVE-2018-4206 (circl-sighting)
- https://support.apple.com/HT208851 (circl)
- 1040744 (circl)
- https://support.apple.com/HT208743 (circl)
- 103957 (circl)
- https://support.apple.com/HT208742 (circl)
- 103958 (circl)
- https://support.apple.com/HT208850 (circl)
…and 4 more exploits
Timeline
- Apr 24, 2018 CVE Published
- Apr 30, 2018 PoC Published
- Apr 30, 2018 PoC Published
- Jan 25, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- May 25, 2022 EPSS Score
- Aug 15, 2022 EPSS Score
References
- https://support.apple.com/HT208850 url
- https://support.apple.com/HT208851 url
- 1040744 vdb
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1529 url
- https://support.apple.com/HT208743 url
- 103957 vdb
- https://support.apple.com/HT208742 url
- 103958 vdb
- 44562 exploit
- https://support.apple.com/en-us/HT208743 advisory
- https://support.apple.com/en-us/HT208742 advisory
- https://support.apple.com/en-us/HT208741 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-4206 advisory
- https://www.exploit-db.com/exploits/44562 url