CVE-2018-4338 is an information disclosure vulnerability in macOS, affecting versions prior to macOS Mojave 10.14, caused by insufficient input sanitization. This medium-severity vulnerability (CVSS 5.5) requires user interaction (UI:R) and local access (AV:L) to exploit, potentially leading to high confidentiality impact (C:H) without affecting integrity or availability. While there is no evidence of active exploitation or public exploit code in Metasploit, Nuclei, or ExploitDB, a Reddit post details a Proof of Concept (PoC) for this now-patched flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.14CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.