CVE-2018-4319
Apple Security Advisory 2018-10-30-12
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Existía un problema de orígenes cruzados con elementos "iframe". Este problema se abordó con una rastreo de orígenes de la seguridad mejorado. El problema afectaba a iOS en versiones anteriores a la 12, watchOS en versiones anteriores a la 5, Safari en versiones anteriores a la 12, iTunes para Windows en versiones anteriores a la 12.9 y iCloud para Windows en versiones anteriores a la 7.7.
APPLE-SA-2018-9-24-3 provides dditional information for
APPLE-SA-2018-9-17-4. Safari 12 is now available and addresses browser history deletion and user interface spoofing vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2018-09-25 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-346: Origin Validation Error
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/kb/HT209106 | 2020-08-24 | |
https://support.apple.com/kb/HT209108 | 2020-08-24 | |
https://support.apple.com/kb/HT209109 | 2020-08-24 | |
https://support.apple.com/kb/HT209140 | 2020-08-24 | |
https://support.apple.com/kb/HT209141 | 2020-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Icloud Search vendor "Apple" for product "Icloud" | < 7.7 Search vendor "Apple" for product "Icloud" and version " < 7.7" | windows |
Affected
| ||||||
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 12.9 Search vendor "Apple" for product "Itunes" and version " < 12.9" | windows |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 12 Search vendor "Apple" for product "Safari" and version " < 12" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 12.0 Search vendor "Apple" for product "Iphone Os" and version " < 12.0" | - |
Affected
|