CVE-2018-4221: Infoleak
Security. An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates.
Other sources
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Security" component. It allows web sites to track users by leveraging the transmission of S/MIME client certificates.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4196
- CVE-2018-4253
- CVE-2018-4256
- CVE-2018-4255
- CVE-2018-4254
- CVE-2018-4258
- CVE-2018-4257
- CVE-2018-7584
- CVE-2018-4219
- CVE-2018-5383
- CVE-2018-4171
- CVE-2018-4194
- CVE-2018-4180
- CVE-2018-4181
- CVE-2018-4182
- CVE-2018-4183
- CVE-2018-4478
- CVE-2018-4251
- CVE-2018-4211
- CVE-2018-4229
- CVE-2018-4159
- CVE-2018-4242
- CVE-2018-4202
- CVE-2018-4217
- CVE-2018-4141
- CVE-2018-4228
- CVE-2018-4236
- CVE-2018-4234
- CVE-2018-4249
- CVE-2018-8897
- CVE-2018-4241
- CVE-2018-4243
- CVE-2018-4237
- CVE-2018-4404
- CVE-2018-4227
- CVE-2018-4235
- CVE-2018-4240
- CVE-2018-4230
- CVE-2018-4221
- CVE-2018-4223
- CVE-2018-4224
- CVE-2018-4225
- CVE-2018-4226
- CVE-2018-4184
- CVE-2018-4198
- CVE-2018-4193
Frequently Asked Questions
What is CVE-2018-4221?
CVE-2018-4221 is a vulnerability that affects certain Apple products including iOS before 11.4 and macOS before 10.13.5.
What is the severity of CVE-2018-4221?
The severity of CVE-2018-4221 is rated as high with a CVSS score of 7.5.
How does CVE-2018-4221 work?
CVE-2018-4221 allows web sites to track users by exploiting the transmission of S/MIME client certificates.
How can I check if I am affected by CVE-2018-4221?
If you are using iOS before 11.4 or macOS before 10.13.5, you may be affected by CVE-2018-4221.
Is there a fix for CVE-2018-4221?
Yes, the issue has been addressed in iOS 11.4 and macOS 10.13.5. It is recommended to update to the latest version to fix the vulnerability.