7.8
CVSSv3

CVE-2018-4280

Published: 03/04/2019 Updated: 05/04/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple watchos

apple iphone os

apple mac os x

apple tvos

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-10-30-14 Additional information for APPLE-SA-2018-7-9-4 macOS High Sierra 10136, Security Update 2018-0 ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-7-23-1 Additional information for APPLE-SA-2018-7-9-4 macOS High Sierra 10136, Security Update 2018-004 ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-7-9-1 iOS 1141 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product Security &lt ...

Github Repositories

osx-security-awesome A collection of OSX/iOS security related resources News Hardening Malware sample sources DFIR Reverse engineering Presentations and Papers Virus and exploit writeups Useful tools and guides Remote Access Toolkits Worth following on Twitter News Linking a microphone The Story of CVE-2018-4184 or how a vulnearbility in OSX's Sp

A collection of OSX and iOS security resources

osx-security-awesome A collection of OSX/iOS security related resources News Hardening Malware sample sources DFIR Reverse engineering Presentations and Papers Virus and exploit writeups Useful tools and guides Remote Access Toolkits Worth following on Twitter News Linking a microphone The Story of CVE-2018-4184 or how a vulnearbility in OSX's Sp

CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.

blanket Blanket is a sandbox escape targeting iOS 1126, although the main vulnerability was only patched in iOS 1141 It exploits a Mach port replacement vulnerability in launchd (CVE-2018-4280), as well as several smaller vulnerabilities in other services, to execute code inside the ReportCrash process, which is unsandboxed, runs as root, and has the task_for_pid-allow en

Awesome Stars A curated list of my GitHub stars! Generated by starred Contents Assembly C C# C++ CSS Dockerfile Go HTML Java JavaScript Jinja LOLCODE Logos Makefile Objective-C Objective-C++ Others Pascal Pawn Perl PowerShell Python Rust Shell Svelte Swift TypeScript Vue Assembly mass1ve-err0r/unibi-OSS - A Collection of full &amp; partial code for CompSci / IT stude