CVE-2018-4467 is a memory corruption vulnerability affecting Apple macOS, which could allow a malicious application to elevate privileges. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L), but once exploited, it can lead to high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, it has received some community discussion and media coverage, indicating awareness of its potential risk. Apple addressed this issue in macOS Mojave 10.14.3 and various security updates for High Sierra and Sierra.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.12.6, < 10.14.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
>= 10.14.1, < 10.14.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 10.14CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.