CVE-2018-4438
published 2019-04-03CVE-2018-4438: A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS…
PriorityP259high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
5.83%
92.4th percentile
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.9 | 7.9 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 12.1.1 | 12.1.1 |
| apple | itunes | < 12.9.2 | 12.9.2 |
| apple | itunes_12.9.2_for_windows | — | — |
| apple | safari | < 12.0.2 | 12.0.2 |
| apple | safari | — | — |
| apple | tvos | < 12.1.1 | 12.1.1 |
| apple | tvos | — | — |
| apple | watchos | < 5.1.2 | 5.1.2 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.22.3-1 (bookworm) | webkit2gtk 2.22.3-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/WebKit/webkit/blob/9ca43a5d4bd8ff63ee7293cac8748d564bd7fbbd/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h#L3481↗
- →The exploit requires two global objects (e.g., via an iframe) to bypass the haveABadTime guard. Look for iframe creation combined with cross-frame Object/Proxy construction and prototype chain manipulation on arrays in JavaScript executed within WebKit-based browsers. ↗
- →The exploit abuses Proxy objects inserted into the prototype chain of native Int32/Double arrays. Detect JavaScript that sets __proto__ of an array or array prototype to a Proxy object, particularly across iframe boundaries. ↗
- →The vulnerability is triggered via the HasIndexedProperty DFG node in JavaScriptCore when the array mode is Int32 or Double and a Proxy is in the prototype chain. The JIT incorrectly assumes no side effects for these array types. Monitor for JIT-compiled code paths involving HasIndexedProperty on arrays with non-standard prototype chains. ↗
- →The exploit uses a timed callback (setTimeout ~500ms) after JIT warm-up loop to trigger the corrupted array state. Behavioral detection: look for tight numeric loops over arrays followed by a delayed callback that reads/writes the same array. ↗
- →Processing maliciously crafted web content triggers this vulnerability. Ensure WebKit-based products are updated: iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9. ↗
- ·The haveABadTime bypass requires two separate global objects. The exploit only works if a second global object (e.g., same-origin iframe) has NOT already had haveABadTime triggered on it, since subsequent calls to haveABadTime have no effect on already-transitioned VMs. ↗
- ·The vulnerability is specific to the DFG JIT compiler's abstract interpreter for HasIndexedProperty on Int32/Double/Contiguous/ArrayStorage array modes. SlowPutArrayStorage arrays are not affected by this incorrect no-side-effect assumption. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4438: watchOS 5.1.2
vendor_apple·2018-12-06·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: watchOS 5.1.2
Apple Security Update: About the security content of watchOS 5.1.2
Product: watchOS
Version: 5.1.2
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Apple
CVE-2018-4438: tvOS 12.1.1
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: tvOS 12.1.1
Apple Security Update: About the security content of tvOS 12.1.1
Product: tvOS
Version: 12.1.1
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Apple
CVE-2018-4438: iOS 12.1.1
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Apple
CVE-2018-4438: iTunes 12.9.2 for Windows
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: iTunes 12.9.2 for Windows
Apple Security Update: About the security content of iTunes 12.9.2 for Windows
Product: iTunes 12.9.2 for Windows
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Apple
CVE-2018-4438: Safari 12.0.2
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: Safari 12.0.2
Apple Security Update: About the security content of Safari 12.0.2
Product: Safari
Version: 12.0.2
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Apple
CVE-2018-4438: iCloud for Windows 7.9
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: iCloud for Windows 7.9
Apple Security Update: About the security content of iCloud for Windows 7.9
Product: iCloud for Windows
Version: 7.9
CVE: CVE-2018-4438
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Debian
CVE-2018-4438: webkit2gtk - A logic issue existed resulting in memory corruption. This was addressed with im...
vendor_debian·2018·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: webkit2gtk - A logic issue existed resulting in memory corruption. This was addressed with im...
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Scope: local
bookworm: resolved (fixed in 2.22.3-1)
bullseye: resolved (fixed in 2.22.3-1)
forky: resolved (fixed in 2.22.3-1)
sid: resolved (fixed in 2.22.3-1)
trixie: resolved (fixed in 2.22.3-1)
GHSA
GHSA-6mmf-48v9-cph4: A logic issue existed resulting in memory corruption
ghsa_unreviewed·2022-05-14
CVE-2018-4438 [HIGH] CWE-119 GHSA-6mmf-48v9-cph4: A logic issue existed resulting in memory corruption
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Project0
JSC Exploits - Project Zero
project_zero·2019-08-01
CVE-2017-2505 JSC Exploits - Project Zero
Posted by Samuel Groß, Project Zero
In this post, we will take a look at the WebKit exploits used to gain an initial foothold onto the iOS device and stage the privilege escalation exploits. All exploits here achieve shellcode execution inside the sandboxed renderer process (WebContent) on iOS. Although Chrome on iOS would have also been vulnerable to these initial browser exploits, they were only used by the attacker to target Safari and iPhones.
After some general discussion, this post first provides a short walkthrough of each of the exploited WebKit bugs and how the attackers construct a memory read/write primitive from them, followed by an overview of the techniques used to gain shellcode execution and how they bypassed existing JIT code injection mitigations, namely the “bulletpr
OSV
CVE-2018-4438: A logic issue existed resulting in memory corruption
osv·2019-04-03·CVSS 8.8
CVE-2018-4438 [HIGH] CVE-2018-4438: A logic issue existed resulting in memory corruption
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
No detection rules found.
No writeups or analysis indexed.
https://support.apple.com/kb/HT209340https://support.apple.com/kb/HT209342https://support.apple.com/kb/HT209343https://support.apple.com/kb/HT209344https://support.apple.com/kb/HT209345https://support.apple.com/kb/HT209346https://support.apple.com/kb/HT209340https://support.apple.com/kb/HT209342https://support.apple.com/kb/HT209343https://support.apple.com/kb/HT209344https://support.apple.com/kb/HT209345https://support.apple.com/kb/HT209346
2019-04-03
Published