Memory corruption in Apple Safari - CVE-2018-4233
Published: June 4, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error in the WebKit component when handling malicious input. A remote unauthenticated attacker can trick the victim into loading a specially crafted content, trigger a memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
watchOS
tvOS
Apple iOS
Opensuse
Ubuntu
Fedora
iCloud for Windows
iTunes
webkitgtk4
webkit2gtk3
How to mitigate CVE-2018-4233
webkit2gtk3 - update to 2.20.3-1.fc28
Links to Public Exploits and PoC-codes
- Exploit #6045 - Safari - Proxy Object Type Confusion (Metasploit) (June 17, 2021)
- Exploit #197 - exploit_playground_lists_androidCVE () (March 18, 2020)
- Exploit #198 - cve-2018-4233 (Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018) (March 18, 2020)
- Exploit #1537 - Safari Proxy Object Type Confusion (March 18, 2020)
- Exploit #1577 - Safari Webkit Proxy Object Type Confusion (March 18, 2020)
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iTunes
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iCloud
- Multiple vulnerabilities in Apple iOS
- Ubuntu update for Webkit2gtk
- OpenSUSE Linux update for webkit2gtk3
- Gentoo update for WebkitGTK+
- OpenSUSE Linux update for webkit2gtk3
- Fedora 27 update for webkitgtk4
- Fedora 28 update for webkit2gtk3