CVE-2018-4390 describes a user interface spoofing vulnerability affecting Apple's iOS, macOS, and watchOS. This flaw, rated Medium severity (CVSS 5.5), could be triggered by processing a maliciously crafted text message, leading to an inconsistent UI and potential deception. While the vulnerability requires user interaction (UI:R), it has no known active exploitation, public exploit code, or significant community discussion. Patches were released in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, Security Update 2017-004 El Capitan, watchOS 4.3, and iOS 12.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.13, < 10.13.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 4.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
< 10.13CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
< 12.1CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.