9.3
CVSSv2

CVE-2018-4109

Published: 03/04/2018 Updated: 27/04/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in certain Apple products. iOS prior to 11.2.5 is affected. tvOS prior to 11.2.5 is affected. watchOS prior to 4.2.2 is affected. The issue involves the "Graphics Driver" component. It allows malicious users to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple apple tv

apple watchos

Github Repositories

Adam Donenfeld's kernel bug for iOS

doadam-videodecoder-bug Adam Donenfeld's kernel bug for iOS Reference to his paper: phrackorg/papers/viewer_discretion_advisedhtml His blog: blogzimperiumcom/cve-2018-4109-overwriting-kernel-memory-video-packets/#W-ycO6YuW7Ftwitter Just modded it into an actual iOS app for convenience