CVE-2018-4428 describes a lock screen bypass vulnerability in Apple iOS that allowed unauthorized access to the share function on a locked device. A local attacker could exploit this by interacting with the device's lock screen to share content, potentially exposing sensitive information. This vulnerability is rated as High severity (CVSS 7.1), indicating a significant impact on confidentiality and integrity with low attack complexity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the issue was addressed in iOS 12.1.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 12.1CPE match | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.