CVE-2018-4438: Buffer Overflow
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
Other sources
WebKit. A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4303
- CVE-2018-4427
- CVE-2018-4431
- CVE-2018-4448
- CVE-2018-4460
- CVE-2018-4435
- CVE-2018-4447
- CVE-2018-4461
- CVE-2018-4436
- CVE-2018-4441
- CVE-2018-4442
- CVE-2018-4443
- CVE-2018-4438
- CVE-2018-4444
- CVE-2018-4437
- CVE-2018-4464
- CVE-2018-4429
- CVE-2018-4440
- CVE-2018-4439
- CVE-2018-4445
- CVE-2018-4465
- CVE-2018-4430
- CVE-2018-4446
- CVE-2018-4428
Frequently Asked Questions
What is CVE-2018-4438?
CVE-2018-4438 is a vulnerability in WebKit that resulted in memory corruption and was addressed with improved state management.
Which software versions are affected by CVE-2018-4438?
CVE-2018-4438 affects versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, and iCloud for Windows 7.9.
How severe is CVE-2018-4438?
CVE-2018-4438 has a severity score of 8.8 (high).
How can I fix CVE-2018-4438?
To fix CVE-2018-4438, you should update your software to iOS 12.1.1 or later, tvOS 12.1.1 or later, watchOS 5.1.2 or later, Safari 12.0.2 or later, iTunes 12.9.2 for Windows or later, and iCloud for Windows 7.9 or later.
Where can I find more information about CVE-2018-4438?
You can find more information about CVE-2018-4438 on the Apple support page: [link](https://support.apple.com/kb/HT209340).