CVE-2018-4435 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.09% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-03 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| apple | iphone os |
| apple | mac os x |
| apple | tvos |
| apple | watchos |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection | 2018-12-11 |
References
- https://support.apple.com/kb/HT209340
- https://support.apple.com/kb/HT209341
- https://support.apple.com/kb/HT209342
- https://support.apple.com/kb/HT209343
- https://support.apple.com/kb/HT209340
- https://support.apple.com/kb/HT209341
- https://support.apple.com/kb/HT209342
- https://support.apple.com/kb/HT209343
→ the Explorer · watch your stack · NVD