Junglewise Threat Intelligence

CVE-2018-4344: Apple Multiple Products Memory Corruption Vulnerability

CVE-2018-4344 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-27

Technologies: Apple watchOS, Apple Tvos, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple iOS, macOS, tvOS, and watchOS was addressed through improved memory handling. The flaw can allow for arbitrary code execution when a user interacts with a malicious file or application.

Affected products

  • Apple iOS < 12.0
  • Apple macOS Mojave < 10.14
  • Apple tvOS < 12.0
  • Apple watchOS < 5.0

Timeline

  • 2019-04-05: disclosed: Initial analysis by NIST
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-27: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats