ZeroHour

CVE-2018-4344

KEVmass

Memory Corruption Flaw in Apple iOS, macOS, tvOS, and watchOS (Pre-2018 Releases)

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2018-4344 is a memory corruption vulnerability (CWE-119) in Apple's operating systems that was fixed with improved memory handling in the Fall 2018 releases. It carries a local attack vector with user interaction required (CVSS AV:L/UI:R), meaning exploitation requires the victim to process attacker-supplied content, and successful exploitation yields high confidentiality, integrity, and availability impact, consistent with potential arbitrary code execution. Every user running versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 is affected, spanning iPhone/iPad, Mac, Apple TV, and Apple Watch. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2022-06-27, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. EPSS currently estimates a 2.9% probability of exploitation within 30 days (86th percentile).

What to do: Upgrade affected devices to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 or later per Apple's instructions, as required by the CISA KEV listing. Inventory your fleet for Apple devices running outdated OS versions; for hardware that cannot run iOS 12, treat the device as permanently unpatched and replace or isolate it. Because the flaw is confirmed exploited in the wild and appears in KEV, prioritize these updates in patch cycles, particularly on user workstations and BYOD endpoints.

Affected
apple iPhone OS (iOS) on iPhone and iPadAll versions prior to iOS 12
apple macOS (mac OS X)All versions prior to macOS Mojave 10.14
apple tvOS on Apple TVAll versions prior to tvOS 12
apple watchOS on Apple WatchAll versions prior to watchOS 5
Estimated exposure
masshundreds of millions of Apple devices ran iOS/macOS/tvOS/watchOS versions below the 2018 fixes at disclosure, with an unknown but likely substantial share… — Based on Apple's installed base of over a billion active iOS devices and broad pre-2018 OS adoption at the time of disclosure, plus public scan and usage-share data showing many devices and Macs still on older, non-upgradable OS versions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os, mac os x, tvos, watchos
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news