CVE-2018-4209: Input Validation
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
Other sources
WebKit. This issue was addressed with improved checks.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4155
- CVE-2018-4142
- CVE-2018-4167
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4185
- CVE-2017-15412
- CVE-2018-4166
- CVE-2018-4157
- CVE-2018-4144
- CVE-2018-4115
- CVE-2018-4113
- CVE-2018-4146
- CVE-2018-4101
- CVE-2018-4114
- CVE-2018-4118
- CVE-2018-4119
- CVE-2018-4120
- CVE-2018-4121
- CVE-2018-4122
- CVE-2018-4125
- CVE-2018-4127
- CVE-2018-4128
- CVE-2018-4129
- CVE-2018-4130
- CVE-2018-4161
- CVE-2018-4162
- CVE-2018-4163
- CVE-2018-4165
- CVE-2018-4207
- CVE-2018-4208
- CVE-2018-4209
- CVE-2018-4210
- CVE-2018-4212
- CVE-2018-4213
- CVE-2018-4145
- CVE-2018-4158
- CVE-2018-4390
- CVE-2018-4391
- CVE-2018-4117
- CVE-2018-4102
- CVE-2018-4116
- CVE-2018-4186
- CVE-2018-4137
- CVE-2018-4133
- CVE-2018-4177
- CVE-2018-4123
- CVE-2018-4168
- CVE-2018-4172
- CVE-2018-4151
- CVE-2018-4187
- CVE-2018-4174
- CVE-2018-4156
- CVE-2018-4134
- CVE-2018-4149
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4140
- CVE-2018-4148
- CVE-2018-4110
- CVE-2018-4131
Frequently Asked Questions
What is CVE-2018-4209?
CVE-2018-4209 is a vulnerability in WebKit that can cause an ASSERT failure due to unexpected interaction.
What is the severity of CVE-2018-4209?
CVE-2018-4209 has a severity score of 8.8, which is considered high.
Which software is affected by CVE-2018-4209?
Affected software includes iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, and iTunes before 12.7.4 for Windows.
How can I fix CVE-2018-4209 on Ubuntu?
To fix CVE-2018-4209 on Ubuntu, update the 'webkit2gtk' package to version 2.22.2-1ubuntu1 or later.
Where can I find more information about CVE-2018-4209?
You can find more information about CVE-2018-4209 on the MITRE CVE website, the OSS Security mailing list, and the WebKitGTK security advisory WSA-2018-0007.