CVE-2018-4407 is a memory corruption vulnerability, categorized as CWE-119, affecting Apple's iOS (prior to 12), macOS Mojave (prior to 10.14), tvOS (prior to 12), and watchOS (prior to 5). It has a high CVSS score of 8.8, indicating a network-exploitable flaw with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its EPSS score of 0.90832 suggests a high probability of exploitation, despite no public exploit code or Metasploit modules being available. Community discussion and media coverage indicate awareness of this patched issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.14CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 12CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 5.0CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.