CVE-2018-4310
Description
An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A sandbox issue in Apple macOS and iOS allowed local apps to access persistent account identifiers, fixed in iOS 12 and macOS Mojave 10.14.
Vulnerability
CVE-2018-4310 is an access issue in Apple iOS and macOS that allowed a local app to read a persistent account identifier. The vulnerability existed in versions prior to iOS 12 and macOS Mojave 10.14. The issue was addressed with additional sandbox restrictions and improved entitlements. [1][2][3]
Exploitation
An attacker would need to have a malicious app installed on the affected device. The app could then access the persistent account identifier without requiring additional privileges or user interaction beyond the initial installation. The attack is local, meaning the attacker must already have code execution capabilities on the device through a downloaded app. [2]
Impact
A successful exploit allows the local app to read a persistent account identifier, which could be used to track or identify the user across sessions or apps. This is a confidentiality breach that could compromise user privacy. The impact is limited to information disclosure and does not grant code execution or system control. [2]
Mitigation
The issue is fixed in iOS 12, released on September 17, 2018, and in macOS Mojave 10.14, released on September 24, 2018. Users should update their devices to the latest version of iOS or macOS. There are no known workarounds for unpatched systems. [1][2][3]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <10.14
- Range: <10.14
- Range: <12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- support.apple.com/kb/HT209106mitrex_refsource_MISC
- support.apple.com/kb/HT209139mitrex_refsource_MISC
- support.apple.com/kb/HT209193mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.