CVE-2018-4139 is a memory corruption vulnerability in the kext tools component of macOS versions prior to 10.13.4. This flaw allows a crafted application to achieve arbitrary code execution with elevated privileges or trigger a denial-of-service condition. Rated with a CVSS score of 7.8 (High), it requires user interaction to exploit but can lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation or Metasploit/Nuclei modules are reported, a proof-of-concept exploit exists on ExploitDB, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.13.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.