CVE-2018-4392: Buffer Overflow
Published Oct 30, 2018
·Updated
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
Other sources
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
Credit
HyungSeok Han, DongHyeon Oh, Sang Kil Cha(KAIST Softsec Lab), Korea, lokihardt(Google Project Zero), zhunki(360 ESG Codesafe Team), ngg, alippai, DirtYiCE, KT(Tresorit working with Trend Micro), Yu Haiwan, Wu Hongjun(Nanyang Technological University working with Trend Micro), 010(Trend Micro)
Affected Software
13 affected componentsFixes available
Apple tvOS<12.1
12.1
Apple WatchOS<5.1
5.1
Apple iCloud for Windows<7.8
7.8
Apple iTunes for Windows<12.9.1
12.9.1
Apple Safari<12.0.1
12.0.1
Apple iOS<12.1
12.1
Apple Safari<12.0.1
Apple iPhone OS<12.1
Apple tvOS<12.1
Apple WatchOS<5.1
Apple iCloud<7.8
Apple iTunes<12.9.1
Microsoft Windows
Event History
Apr 3, 2019
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4398
- CVE-2018-4394
- CVE-2018-4371
- CVE-2018-4420
- CVE-2018-4413
- CVE-2018-4419
- CVE-2018-4381
- CVE-2018-4369
- CVE-2018-4372
- CVE-2018-4382
- CVE-2018-4386
- CVE-2018-4392
- CVE-2018-4416
- CVE-2018-4409
- CVE-2018-4378
- CVE-2018-4368
- CVE-2018-4384
- CVE-2018-4374
- CVE-2018-4377
- CVE-2018-4400
- CVE-2018-4373
- CVE-2018-4375
- CVE-2018-4376
- CVE-2018-4339
- CVE-2018-4365
- CVE-2018-4366
- CVE-2018-4367
- CVE-2018-4427
- CVE-2018-4390
- CVE-2018-4391
- CVE-2018-4388
- CVE-2018-4387
- CVE-2018-4385
Frequently Asked Questions
1
What is CVE-2018-4392?
CVE-2018-4392 is a vulnerability in WebKit that allows for multiple memory corruption issues.
2
Which versions of iOS are affected by CVE-2018-4392?
Versions prior to iOS 12.1 are affected by CVE-2018-4392.
3
Which versions of Safari are affected by CVE-2018-4392?
Safari version 12.0.1 and prior are affected by CVE-2018-4392.
4
How can I fix CVE-2018-4392 on my device?
Update to iOS 12.1 or later to fix CVE-2018-4392 on your device.
5
Where can I find more information about CVE-2018-4392?
You can find more information about CVE-2018-4392 on the Apple support website.