CVE-2018-4404 is a critical memory corruption vulnerability affecting Apple iOS before version 11.4 and macOS High Sierra before 10.13.5, stemming from inadequate memory handling. This high-severity flaw (CVSS 7.8) can be triggered locally with user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV, exploit intelligence indicates the availability of a Metasploit module (Safari Proxy Object Type Confusion), and it has garnered significant community discussion and media coverage, including its association with the "LightSpy" spyware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.13.0, < 10.13.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.