cbcvebase.
CVE-2018-4312
published 2019-04-03

CVE-2018-4312: A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for…

PriorityP178high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
9.35%
94.8th percentile
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.77.7
appleicloud_for_windows
appleios
appleiphone_os< 12.012.0
appleitunes< 12.912.9
appleitunes_12.9_for_windows
applesafari< 1212
applesafari
appletvos< 1212
appletvos
debianwebkit2gtk< webkit2gtk 2.22.0-2 (bookworm)webkit2gtk 2.22.0-2 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by processing maliciously crafted web content via WebKit's AXObjectCache::handleMenuItemSelected, leading to a use-after-free condition exploitable for arbitrary code execution.
  • The crash/UAF occurs inside WebCore::AXObjectCache::handleMenuItemSelected; monitor for WebKit renderer crashes in this function as a potential exploitation indicator.
  • Exploitation vector is web content delivery; any Safari/WebKit-based browser processing untrusted web content on unpatched iOS <12, tvOS <12, Safari <12, iTunes <12.9, or iCloud for Windows <7.7 is at risk.
  • ·The PoC exploit JS function (jsfuzzer) is truncated in the source and does not provide a complete, standalone trigger; the full trigger logic is not available from the provided sources.
  • ·The vulnerability affects WebKit versions prior to the fix: iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. On Debian, the fix is in webkit2gtk 2.22.0-2.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.