Type confusion in Apple Safari - CVE-2018-4246
Published: June 2, 2018 / Updated: June 4, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to type confusion in the WebKit component when handling malicious input. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
webkit2gtk (Alpine package)
webkitgtk4
webkit2gtk3
watchOS
tvOS
Apple iOS
Fedora
Opensuse
iCloud for Windows
iTunes
How to mitigate CVE-2018-4246
webkitgtk4 - update to 2.20.3-1.fc27
webkit2gtk3 - update to 2.20.3-1.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iTunes
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iCloud
- Multiple vulnerabilities in Apple iOS
- OpenSUSE Linux update for webkit2gtk3
- Type confusion in webkit2gtk (Alpine package)
- Fedora 27 update for webkitgtk4
- Fedora 28 update for webkit2gtk3