CVE-2018-4448 is a memory initialization vulnerability affecting Apple's iOS, macOS, tvOS, and watchOS, where improved memory handling was required. A local attacker could exploit this with low complexity to read kernel memory, leading to a high confidentiality impact. Rated 5.5 (Medium), this vulnerability has no known public exploits, Metasploit modules, or significant community discussion, and is not listed on CISA's KEV catalog. The issue was addressed in various Apple updates, including macOS Mojave 10.14.4 and iOS 12.1.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.12.6, < 10.14.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 12.1.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 5.1.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
>= 10.13.6, < 10.14.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.