CVE-2018-4176 describes a vulnerability in macOS versions prior to 10.13.4, specifically within the "Disk Images" component. This flaw allows an attacker to trigger an application launch simply by a user mounting a specially crafted disk image. Rated Medium with a CVSS score of 5.5, the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and local access (AV:L), potentially leading to high impact on integrity (I:H) by executing arbitrary code. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in CISA's KEV catalog, it has received some media coverage and community discussion, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.13.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.