High severity7.8NVD Advisory· Published Apr 3, 2018· Updated Jun 17, 2026
CVE-2018-4131
CVE-2018-4131
Description
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "WindowServer" component. It allows attackers to bypass the Secure Input Mode protection mechanism, and log keystrokes of arbitrary apps, via a crafted app that scans key states.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <10.13.4
- Range: <11.3
Patches
Vulnerability mechanics
References
6- www.securityfocus.com/bid/103581nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040604nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040608nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT208692nvdVendor Advisory
- support.apple.com/HT208693nvdVendor Advisory
- twitter.com/boastr_net/status/979624397664333824nvdThird Party Advisory
News mentions
0No linked articles in our index yet.