CVE-2018-4139
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
- Affected products
- Apple Macos
- Apple Mac Os X
- < 10.13.4
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 4.4% (90th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2018-04-03
CVE-2018-4139 at NVD
4 known exploits for CVE-2018-4139
Proof-of-concept code and exploit modules indexed by Sploitus
iOS / macOS - task_swap_mach_voucher() Use-After-Free Exploit
iOSmacOS - task_swap_mach_voucher() Use-After-Free
macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rul
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules