CVE-2018-4110: Critical severity apple ios and ipados vulnerability
Published Mar 29, 2018
·Updated
Web App. A cookie management issue was addressed with improved state management.
Other sources
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" component. It allows remote attackers to bypass intended restrictions on cookie persistence.
Credit
Ben Compton, Jason Colley(Cerner Corporation)
Affected Software
2 affected componentsFixes available
Apple iOS and iPadOS<11.3
11.3
iPhone OS<11.3
Event History
Apr 3, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4177
- CVE-2018-4123
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2018-4390
- CVE-2018-4391
- CVE-2018-4167
- CVE-2018-4168
- CVE-2018-4172
- CVE-2018-4151
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4185
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4174
- CVE-2018-4166
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4134
- CVE-2018-4137
- CVE-2018-4149
- CVE-2018-4144
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4140
- CVE-2018-4148
- CVE-2018-4110
- CVE-2018-4101
- CVE-2018-4114
- CVE-2018-4118
- CVE-2018-4119
- CVE-2018-4120
- CVE-2018-4121
- CVE-2018-4122
- CVE-2018-4125
- CVE-2018-4127
- CVE-2018-4128
- CVE-2018-4129
- CVE-2018-4130
- CVE-2018-4161
- CVE-2018-4162
- CVE-2018-4163
- CVE-2018-4165
- CVE-2018-4113
- CVE-2018-4146
- CVE-2018-4117
- CVE-2018-4207
- CVE-2018-4208
- CVE-2018-4209
- CVE-2018-4210
- CVE-2018-4212
- CVE-2018-4213
- CVE-2018-4145
- CVE-2018-4131
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-4110.
2
What is the severity of CVE-2018-4110?
CVE-2018-4110 has a severity rating of 9.8 (Critical).
3
Which Apple products are affected by CVE-2018-4110?
iOS before version 11.3 is affected by CVE-2018-4110.
4
What is the impact of CVE-2018-4110?
CVE-2018-4110 allows remote attackers to bypass intended restrictions on cookie persistence.
5
Is there a fix available for CVE-2018-4110?
Yes, a fix is available. Users should update to iOS version 11.3 or later.