CVE-2018-4124
An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character.
- Affected products
- Coretext, Ios, Apple Macos, Tvos, Watchos
- Apple Iphone Os
- < 11.2.6
- Apple Mac Os X
- < 10.13.3
- Apple Tvos
- < 11.2.6
- Apple Watchos
- < 4.2.3
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 6.0% (93th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2018-04-03
CVE-2018-4124 at NVD
1 known exploit for CVE-2018-4124
Proof-of-concept code and exploit modules indexed by Sploitus