cbcvebase.
CVE-2018-4233
published 2018-06-08

CVE-2018-4233: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
53.77%
98.9th percentile
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.57.5
appleicloud_for_windows
appleios
appleiphone_os< 11.411.4
appleitunes< 12.7.512.7.5
appleitunes_12.7.5_for_windows
applesafari< 11.1.111.1.1
applesafari
appletvos< 11.411.4
appletvos
applewatchos< 4.3.14.3.1
applewatchos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianwebkit2gtk< webkit2gtk 2.20.3-1 (bookworm)webkit2gtk 2.20.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

filename20004312341.png
filenamessudo
filenameddss
filenamemac.zip
filenameupdate
filenameupdate.plist
processmacircloader
pathdata/exploits/CVE-2018-4233/stage1.bin
otherPAYLOAD_CMD_PLACEHOLDER
  • The exploit targets macOS 10.13.3 and earlier via a crafted web page delivered through Safari; user-agent strings containing 'Intel Mac OS X' versions below 10.13.4 should be treated as vulnerable and monitored for exploitation attempts.
  • A MachO binary masquerading as a PNG file (magic bytes mismatch) named '20004312341.png' is an initial-stage delivery artifact; detect MachO files with .png extensions on macOS endpoints.
  • Presence of the process or binary 'macircloader' on a macOS host is a strong indicator of LightSpy Core deployment following CVE-2018-4233 exploitation.
  • The exploit uses a Javascript Proxy / CreateThis type confusion in WebKit's DFG JIT; network-level detection should look for delivery of exploit JS that manipulates Proxy objects to corrupt JIT-compiled structures.
  • The Metasploit module for CVE-2018-4233 uses the default payload 'python/meterpreter/reverse_tcp'; monitor for outbound reverse TCP meterpreter connections from Safari child processes on macOS.
  • The JIT region is overwritten with shellcode as part of exploitation; memory-protection or exploit-guard telemetry showing executable-region writes within the Safari/JavaScriptCore process is a key detection signal.
  • Post-exploitation persistence is established by configuring the 'update' binary to run at startup via a plist; monitor for new LaunchAgent/LaunchDaemon plist entries referencing an 'update' binary dropped alongside 'update.plist'.
  • The exploit checks the macOS version from the User-Agent header; web server logs showing version extraction regex against 'Intel Mac OS X' followed by exploit page delivery are indicative of active exploitation.
  • ·The Metasploit module only supports macOS 10.12.6, 10.13, and 10.13.3 via hardcoded offset tables; versions 10.13.4 and above are explicitly flagged as not vulnerable by the module.
  • ·The iOS variant of the exploit (webkit_createthis.rb) chains CVE-2018-4233 with CVE-2017-13861 (async_wake) for kernel TFP0 and trust-cache manipulation, making it a distinct multi-stage chain from the macOS variant.
  • ·LightSpy macOS activity observed since at least January 2024 appears limited to testing environments; confirmed victim count in production is low per ThreatFabric's panel access.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.