Resource exhaustion in Apple iOS - CVE-2018-4409
Published: October 31, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to resource exhaustion in Webkit component when handling malicious input. A remote attacker can trick the victim into visiting a specially crafted website, consume excessive resources and cause the service to crash.
Affected software
tvOS
iCloud for Windows
Apple Safari
iTunes
How to mitigate CVE-2018-4409
iCloud for Windows - update to 7.8
tvOS - update to 12.1
Apple Safari - update to 12.0.1
iTunes - update to 12.9.1