Vulnerability record · CVE-2018-4344 · published 3 April 2019
CVE-2018-4344: Apple iOS, macOS, tvOS and watchOS memory corruption flaw
Apple · Iphone Os
A memory corruption issue in Apple iOS, macOS Mojave, tvOS and watchOS was fixed through improved memory handling. The flaw is a memory buffer overflow (CWE-119) that can be triggered by processing maliciously crafted input, and it affects all four platforms before the listed OS releases. It matters because it allows code execution in the context of the affected process and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA's KEV catalog with known exploitation and a CVSS of 7.8, but it requires local access and user interaction, which limits mass exploitation.
What it is
A memory corruption issue in Apple iOS, macOS Mojave, tvOS and watchOS was fixed through improved memory handling. The flaw is a memory buffer overflow (CWE-119) that can be triggered by processing maliciously crafted input, and it affects all four platforms before the listed OS releases. It matters because it allows code execution in the context of the affected process and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who successfully triggers the corruption can achieve code execution with high confidentiality, integrity and availability impact within the affected process. The CVSS vector indicates full loss of confidentiality, integrity and availability on the vulnerable component.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the flaw is reached by getting a user to open or process a crafted file or other local input. No remote network vector is described in the record.
Exploitation
CVE-2018-4344 is in CISA's KEV catalog with a 2022-07-18 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.02908 (86th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Apple security updates referenced in advisories HT209106, HT209107, HT209108 and HT209139 to bring iOS, macOS Mojave, tvOS and watchOS to the fixed versions.
- Prioritize patching for any internet-facing or high-value Apple endpoints, since the flaw is on the KEV catalog.
- Restrict user handling of untrusted files and media on unpatched Apple devices where patching cannot be completed immediately.
- Track KEV remediation deadlines and verify that all four affected platforms, not just iOS, are updated.
Detection
- Monitor for crashes or abnormal process termination in Apple media, document or system components that could indicate memory corruption attempts.
- Hunt for suspicious files or attachments delivered to Apple endpoints that are opened by users, correlating with process execution around the time of the crash.
- Check endpoint inventory and patch management data for iOS, macOS, tvOS and watchOS versions below the fixed releases named in the Apple advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-4344 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/kb/HT209106 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209107 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209108 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209139 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209106 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209107 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209108 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT209139 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-4344 | US Government Resource |
Track CVE-2018-4344 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.