Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-4280Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Tvos

Severity
7.8HIGHNVD
EPSS
18.6%
top 4.73%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 3
Latest updateMay 14

Description

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

🔴Vulnerability Details

1
GHSA
GHSA-49mg-c54c-h35r: A memory corruption issue was addressed with improved memory handling2022-05-14

💥Exploits & PoCs

1
Exploit-DB
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free2019-01-25

📋Vendor Advisories

4
Apple
CVE-2018-4280: iOS 11.4.12018-07-09
Apple
CVE-2018-4280: watchOS 4.3.22018-07-09
Apple
CVE-2018-4280: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan2018-07-09
Apple
CVE-2018-4280: tvOS 11.4.12018-07-09