CVE-2018-4323 is a high-severity memory corruption vulnerability, specifically a use-after-free issue in WebKit's WebCore component, affecting Apple products including iOS, tvOS, Safari, iTunes for Windows, and iCloud for Windows versions prior to their respective 12.x releases. This vulnerability, with a CVSS score of 8.8, could allow an unauthenticated attacker to achieve high impact on confidentiality, integrity, and availability through user interaction, likely via a malicious website. While not listed in CISA's KEV catalog, a public exploit (EDB-45484) exists, and the vulnerability has garnered significant community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 12.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 12CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 7.7CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:* | ||
< 12.9CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.