Spoofing attack in Apple iOS - CVE-2018-4440
Published: December 6, 2018
Vulnerability identifier: #VU16297
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4440
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct spoofing attack on the target system.
The weakness exists due to insufficient validation of user-supplied input in the Safari component. A remote attacker can trick the victim into visiting a specially crafted website, trigger state management error and spoof address bar.
Affected software
Apple iOS
iCloud for Windows
Apple Safari
iTunes
iCloud for Windows
Apple Safari
iTunes
How to mitigate CVE-2018-4440
Update to version 12.1.1.
Apple iOS - update to 12.1.1 16C50
iCloud for Windows - update to 7.9
Apple Safari - update to 12.0.2
iTunes - update to 12.9.2
iCloud for Windows - update to 7.9
Apple Safari - update to 12.0.2
iTunes - update to 12.9.2