CVE-2018-4185
published 2019-01-11CVE-2018-4185: In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.95%
85.8th percentile
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11.3 | 11.3 |
| apple | mac_os_x | < 10.13.4 | 10.13.4 |
| apple | macos_high_sierra_10.13.4_security_update_2018-002_sierra_and_security_update_20 | — | — |
| apple | tvos | < 11.3 | 11.3 |
| apple | tvos | — | — |
| apple | watchos | < 4.3 | 4.3 |
| apple | watchos | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4185: watchOS 4.3
vendor_apple·2018-03-29·CVSS 7.5
CVE-2018-4185 [HIGH] CVE-2018-4185: watchOS 4.3
Apple Security Update: About the security content of watchOS 4.3
Product: watchOS
Version: 4.3
CVE: CVE-2018-4185
Component: Kernel
Impact: A malicious application may be able to determine kernel memory layout
Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
Apple
CVE-2018-4185: tvOS 11.3
vendor_apple·2018-03-29·CVSS 7.5
CVE-2018-4185 [HIGH] CVE-2018-4185: tvOS 11.3
Apple Security Update: About the security content of tvOS 11.3
Product: tvOS
Version: 11.3
CVE: CVE-2018-4185
Component: Kernel
Impact: A malicious application may be able to determine kernel memory layout
Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
Apple
CVE-2018-4185: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
vendor_apple·2018-03-29·CVSS 7.5
CVE-2018-4185 [HIGH] CVE-2018-4185: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
Product: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
CVE: CVE-2018-4185
Component: Kernel
Impact: A malicious application may be able to determine kernel memory layout
Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
Apple
CVE-2018-4185: iOS 11.3
vendor_apple·2018-03-29·CVSS 7.5
CVE-2018-4185 [HIGH] CVE-2018-4185: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4185
Component: Kernel
Impact: A malicious application may be able to determine kernel memory layout
Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
GHSA
GHSA-63w4-m2q2-xw9v: In iOS before 11
ghsa_unreviewed·2022-05-14
CVE-2018-4185 [HIGH] CWE-200 GHSA-63w4-m2q2-xw9v: In iOS before 11
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-11
Published