CVE-2018-4306 is a critical use-after-free vulnerability in WebKit, affecting Apple products including iOS prior to version 12, tvOS prior to version 12, Safari prior to version 12, iTunes 12.9 for Windows, and iCloud for Windows 7.7. With a CVSS score of 8.8 (HIGH), it allows for remote code execution with high impact on confidentiality, integrity, and availability, typically requiring user interaction. While not listed in CISA's KEV catalog, an exploit (EDB-45482) exists on ExploitDB, and it has received notable community discussion and media coverage, indicating awareness of its potential. Despite its age, its high FAUCET Risk Score of 97/100 suggests continued relevance for systems that have not been updated.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 12.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 12CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 7.7CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:* | ||
< 12.9CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.