CERT-In Advisory
CIAD-2018-0021
Multiple Vulnerabilities in Apple Safari
Original Issue Date: July 25, 2018
Severity Rating: High
Software Affected
- Apple Safari versions prior to 11.1.2
Overview
Multiple vulnerabilities have been reported in Apple Safari which could be exploited by a remote attacker to spoof URLs in the address bar, exfiltrate audio, execute remote code or cause denial of service conditions.
Description
Multiple vulnerabilities exist in Apple Safari due to improper handling of user-supplied input, multiple memory corruption issues, improper state management or cross-origin access error in various components within WebKit and Safari component. A remote attacker could exploit these vulnerabilities by persuading the user to open a specially crafted webpage.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, spoof address bar, exfiltrate audio or cause denial of service conditions.
Solution
Apply appropriate security updates as mentioned in the Apple Security Updates
https://support.apple.com/en-gb/HT208934
Vendor Information
Apple
https://support.apple.com/en-gb/HT208934
References
Apple
https://support.apple.com/en-gb/HT208934
Security Tracker
https://securitytracker.com/id/1041232
https://securitytracker.com/id/1041234
CVE Name
CVE-2018-4279
CVE-2018-4270
CVE-2018-4278
CVE-2018-4284
CVE-2018-4266
CVE-2018-4261
CVE-2018-4262
CVE-2018-4263
CVE-2018-4264
CVE-2018-4265
CVE-2018-4267
CVE-2018-4272
CVE-2018-4271
CVE-2018-4273
CVE-2018-4274
CVE-2018-4260
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|