CVE-2018-4442
published 2019-04-03CVE-2018-4442: A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari…
PriorityP259high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
5.83%
92.3th percentile
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.9 | 7.9 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 12.1.1 | 12.1.1 |
| apple | itunes | < 12.9.2 | 12.9.2 |
| apple | itunes_12.9.2_for_windows | — | — |
| apple | safari | < 12.0.2 | 12.0.2 |
| apple | safari | — | — |
| apple | tvos | < 12.1.1 | 12.1.1 |
| apple | tvos | — | — |
| apple | watchos | < 5.1.2 | 5.1.2 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.22.3-1 (bookworm) | webkit2gtk 2.22.3-1 (bookworm) |
| sympa | sympa | >= 0 < 6.1.24~dfsg-1ubuntu0.1~esm1 | 6.1.24~dfsg-1ubuntu0.1~esm1 |
| sympa | sympa | >= 0 < 6.2.24~dfsg-1ubuntu0.1~esm1 | 6.2.24~dfsg-1ubuntu0.1~esm1 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-4ubuntu0.20.04.1~esm1 | 6.2.40~dfsg-4ubuntu0.20.04.1~esm1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is a Use-After-Free in WebKit JSC JIT triggered via GetIndexedPropertyStorage on rope strings. Detection should focus on JIT-compiled JavaScript that allocates large rope strings (concatenations of multi-MB strings) followed by forced garbage collection cycles, which is the exploit primitive. ↗
- →Exploit pattern involves JIT-warming a function with 10,000 iterations over rope-string arrays, then triggering GC via repeated large ArrayBuffer allocations (10 × 10 MB). Monitor for JavaScript contexts allocating unusually large ArrayBuffers in rapid succession as a GC-forcing technique. ↗
- →The exploit constructs rope strings by concatenating two 2 MB repeated strings ('a'.repeat(1024*1024*2) + 'b'.repeat(1024*1024*2)) to create objects eligible for GetIndexedPropertyStorage. Heuristic detection of very large string concatenations in JIT-optimised paths may surface exploitation attempts. ↗
- →Trigger condition is 'Processing maliciously crafted web content' leading to arbitrary code execution via WebKit memory corruption. Any Safari, WebKit-based browser, iTunes, or iCloud for Windows process loading untrusted web content on unpatched versions should be treated as at-risk. ↗
- ·Affected versions span multiple Apple products; patched versions are iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, and iCloud for Windows 7.9. Ensure all WebKit-embedding products are updated, not just Safari. ↗
- ·On Debian-based Linux systems (webkit2gtk), the vulnerability is resolved in package version 2.22.3-1 across all tracked suites (bookworm, bullseye, forky, sid, trixie). Verify installed webkit2gtk version is ≥ 2.22.3-1. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian8.8LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-4442: watchOS 5.1.2
vendor_apple·2018-12-06·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: watchOS 5.1.2
Apple Security Update: About the security content of watchOS 5.1.2
Product: watchOS
Version: 5.1.2
CVE: CVE-2018-4442
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4442: iCloud for Windows 7.9
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: iCloud for Windows 7.9
Apple Security Update: About the security content of iCloud for Windows 7.9
Product: iCloud for Windows
Version: 7.9
CVE: CVE-2018-4442
Component: WebK it
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4442: tvOS 12.1.1
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: tvOS 12.1.1
Apple Security Update: About the security content of tvOS 12.1.1
Product: tvOS
Version: 12.1.1
CVE: CVE-2018-4442
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4442: Safari 12.0.2
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: Safari 12.0.2
Apple Security Update: About the security content of Safari 12.0.2
Product: Safari
Version: 12.0.2
CVE: CVE-2018-4442
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4442: iTunes 12.9.2 for Windows
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: iTunes 12.9.2 for Windows
Apple Security Update: About the security content of iTunes 12.9.2 for Windows
Product: iTunes 12.9.2 for Windows
CVE: CVE-2018-4442
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2018-4442: iOS 12.1.1
vendor_apple·2018-12-05·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4442
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved memory handling.
Debian
CVE-2018-4442: webkit2gtk - A memory corruption issue was addressed with improved memory handling. This issu...
vendor_debian·2018·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: webkit2gtk - A memory corruption issue was addressed with improved memory handling. This issu...
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Scope: local
bookworm: resolved (fixed in 2.22.3-1)
bullseye: resolved (fixed in 2.22.3-1)
forky: resolved (fixed in 2.22.3-1)
sid: resolved (fixed in 2.22.3-1)
trixie: resolved (fixed in 2.22.3-1)
GHSA
GHSA-vg9h-c983-qq74: A memory corruption issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-14
CVE-2018-4442 [HIGH] CWE-119 GHSA-vg9h-c983-qq74: A memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
OSV
sympa vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2020-10936 sympa vulnerabilities
sympa vulnerabilities
USN-4442-1 fixed vulnerabilities in Sympa. This update provides the
corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu
20.04 ESM. Original advisory details:
Nicolas Chatelain discovered that Sympa incorrectly handled environment
variables. An attacker could possibly use this issue with a setuid
binary and gain root privileges. (CVE-2020-10936)
Michael Kaczmarczik discovered that Sympa incorrectly handled HTTP
GET/POST requests. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected Ubuntu 16.04
ESM and Ubuntu 18.04 ESM. (CVE-2018-1000550)
It was discovered that Sympa incorrectly handled URL parameters. An
attacker could possibly use this issue to perform XSS attacks. This issue only
Project0
JSC Exploits - Project Zero
project_zero·2019-08-01
CVE-2017-2505 JSC Exploits - Project Zero
Posted by Samuel Groß, Project Zero
In this post, we will take a look at the WebKit exploits used to gain an initial foothold onto the iOS device and stage the privilege escalation exploits. All exploits here achieve shellcode execution inside the sandboxed renderer process (WebContent) on iOS. Although Chrome on iOS would have also been vulnerable to these initial browser exploits, they were only used by the attacker to target Safari and iPhones.
After some general discussion, this post first provides a short walkthrough of each of the exploited WebKit bugs and how the attackers construct a memory read/write primitive from them, followed by an overview of the techniques used to gain shellcode execution and how they bypassed existing JIT code injection mitigations, namely the “bulletpr
OSV
CVE-2018-4442: A memory corruption issue was addressed with improved memory handling
osv·2019-04-03·CVSS 8.8
CVE-2018-4442 [HIGH] CVE-2018-4442: A memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
No detection rules found.
No writeups or analysis indexed.
https://support.apple.com/kb/HT209340https://support.apple.com/kb/HT209342https://support.apple.com/kb/HT209343https://support.apple.com/kb/HT209344https://support.apple.com/kb/HT209345https://support.apple.com/kb/HT209346https://support.apple.com/kb/HT209340https://support.apple.com/kb/HT209342https://support.apple.com/kb/HT209343https://support.apple.com/kb/HT209344https://support.apple.com/kb/HT209345https://support.apple.com/kb/HT209346
2019-04-03
Published