CERT-In Advisory
CIAD-2018-0024
Multiple Vulnerabilities in Apple iOS
Original Issue Date: September 19, 2018
Severity Rating: High
Software Affected
- Apple iOS versions prior to 12
Overview
Multiple vulnerabilities have been reported in Apple iOS which could be exploited by an attacker to spoof contents, disclose sensitive information, bypass security restrictions, execute arbitrary code, or gain elevated privileges of the target system.
Description
Multiple vulnerabilities exist in the different components of Apple iOS due to varied causes like improper handling of user-supplied input, permissions issue, memory corruption issues, improper state management or weaknesses in the RC4 cryptographic algorithm. A remote attacker could exploit some of these vulnerabilities by persuading the user to open a specially crafted webpage.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, disclose sensitive information, intercept Bluetooth traffic, read the target user¿s deleted messages, view the websites that the user had visited, spoof address bars, exfiltrate data, or gain elevated privileges of the target system.
Solution
Apply appropriate security updates as mentioned in the
Apple Security Advisory
Vendor Information
Apple
https://support.apple.com/en-us/HT209106
References
Apple
https://support.apple.com/en-us/HT209106
Security Tracker
https://securitytracker.com/id/1041665
CVE Name
CVE-2018-4322
CVE-2018-5383
CVE-2018-4356
CVE-2018-4335
CVE-2018-4305
CVE-2018-4363
CVE-2018-4313
CVE-2018-4352
CVE-2018-4329
CVE-2018-4307
CVE-2018-4362
CVE-2016-1777
CVE-2018-4325
CVE-2018-4338
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|