CVE-2018-4399Improper Input Validation in Apple Tvos

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 48.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 14

Description

An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

🔴Vulnerability Details

1
GHSA
GHSA-2c94-6r37-w92p: An access issue existed with privileged API calls2022-05-14

📋Vendor Advisories

5
Apple
CVE-2018-4399: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra2018-10-30
Apple
CVE-2018-4399: macOS Mojave 10.142018-09-24
Apple
CVE-2018-4399: tvOS 122018-09-17
Apple
CVE-2018-4399: iOS 122018-09-17
Apple
CVE-2018-4399: watchOS 52018-09-17