Memory corruption in Apple iOS - CVE-2018-4443
Published: December 6, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to boundary error in the Webkit component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
watchOS
tvOS
Opensuse
WebKitGTK+
iCloud for Windows
Apple Safari
iTunes
How to mitigate CVE-2018-4443
WebKitGTK+ - update to 2.22.3
watchOS - update to 5.1.2
iCloud for Windows - update to 7.9
tvOS - update to 12.1.1
Apple Safari - update to 12.0.2
iTunes - update to 12.9.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS
- Multiple vulnerabilities in Apple iTunes
- Multiple vulnerabilities in Apple iCloud
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Remote code execution in WebKitGTK+
- OpenSUSE Linux update for webkit2gtk3
- OpenSUSE Linux update for webkit2gtk3