← Vulnerability feed

Vulnerability record · CVE-2018-4344 · published 3 April 2019

CVE-2018-4344: Apple iOS, macOS, tvOS and watchOS memory corruption flaw

Apple · Iphone Os

A memory corruption issue in Apple iOS, macOS Mojave, tvOS and watchOS was fixed through improved memory handling. The flaw is a memory buffer overflow (CWE-119) that can be triggered by processing maliciously crafted input, and it affects all four platforms before the listed OS releases. It matters because it allows code execution in the context of the affected process and is listed in CISA's Known Exploited Vulnerabilities catalog.

7.8 CVSS 3.1 High CISA KEV since 27 Jun 2022 EPSS 2.4% · top 16.8% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 9.3
2.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA's KEV catalog with known exploitation and a CVSS of 7.8, but it requires local access and user interaction, which limits mass exploitation.

What it is

A memory corruption issue in Apple iOS, macOS Mojave, tvOS and watchOS was fixed through improved memory handling. The flaw is a memory buffer overflow (CWE-119) that can be triggered by processing maliciously crafted input, and it affects all four platforms before the listed OS releases. It matters because it allows code execution in the context of the affected process and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker who successfully triggers the corruption can achieve code execution with high confidentiality, integrity and availability impact within the affected process. The CVSS vector indicates full loss of confidentiality, integrity and availability on the vulnerable component.

Attack surface

The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the flaw is reached by getting a user to open or process a crafted file or other local input. No remote network vector is described in the record.

Exploitation

CVE-2018-4344 is in CISA's KEV catalog with a 2022-07-18 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.02908 (86th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Apple security updates referenced in advisories HT209106, HT209107, HT209108 and HT209139 to bring iOS, macOS Mojave, tvOS and watchOS to the fixed versions.
  • Prioritize patching for any internet-facing or high-value Apple endpoints, since the flaw is on the KEV catalog.
  • Restrict user handling of untrusted files and media on unpatched Apple devices where patching cannot be completed immediately.
  • Track KEV remediation deadlines and verify that all four affected platforms, not just iOS, are updated.

Detection

  • Monitor for crashes or abnormal process termination in Apple media, document or system components that could indicate memory corruption attempts.
  • Hunt for suspicious files or attachments delivered to Apple endpoints that are opened by users, correlating with process execution around the time of the crash.
  • Check endpoint inventory and patch management data for iOS, macOS, tvOS and watchOS versions below the fixed releases named in the Apple advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-4344 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://support.apple.com/kb/HT209106 Release NotesVendor Advisory
https://support.apple.com/kb/HT209107 Release NotesVendor Advisory
https://support.apple.com/kb/HT209108 Release NotesVendor Advisory
https://support.apple.com/kb/HT209139 Release NotesVendor Advisory
https://support.apple.com/kb/HT209106 Release NotesVendor Advisory
https://support.apple.com/kb/HT209107 Release NotesVendor Advisory
https://support.apple.com/kb/HT209108 Release NotesVendor Advisory
https://support.apple.com/kb/HT209139 Release NotesVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-4344 US Government Resource

Track CVE-2018-4344 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 22%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed9.8CVE-2025-31200Apple OS media parsing memory corruption allows code executionA memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 19%analysed9.8CVE-2025-31201Apple OS Pointer Authentication bypass via arbitrary read/writeApple removed vulnerable code that allowed an attacker holding arbitrary read and write capability to bypass Pointer Authentication across iOS, iPadO…KEVEPSS 14%analysed9.8CVE-2022-22587Apple iOS, iPadOS and macOS kernel memory corruption via out-of-bounds writeAn out-of-bounds write (CWE-787) in Apple iOS, iPadOS and macOS is caused by insufficient input validation and can corrupt memory. Apple states it is…KEVEPSS 12%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2018-4344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.