CVE-2018-4334
Description
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory corruption issue in macOS prior to 10.14 could allow a remote attacker to execute arbitrary code via an HTTP client targeting AFP servers.
Vulnerability
CVE-2018-4334 is a memory corruption vulnerability in the AFP server (afpserver) component of macOS. The issue affects macOS versions prior to 10.14 Mojave, including macOS Sierra 10.12.6 and High Sierra 10.13.6 [1]. The vulnerability arises due to improper memory handling when processing certain HTTP requests [1].
Exploitation
An attacker situated remotely can exploit this vulnerability by crafting a malicious HTTP request sent to an AFP server [1]. No authentication is required for successful exploitation. The attacker does not need any special network position beyond being able to communicate with the vulnerable server.
Impact
Successful exploitation could lead to memory corruption, which may allow an attacker to execute arbitrary code on the target system [1]. This could potentially result in full compromise of the affected Mac, including unauthorized access to data, installation of malware, or further network attacks.
Mitigation
The vulnerability was fixed in macOS Mojave 10.14, released on September 24, 2018 [2]. Users running older versions (Sierra 10.12.6 or High Sierra 10.13.6) should update to the latest available security update or upgrade to macOS Mojave [1]. No workarounds are mentioned.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.14
- Range: Versions prior to: macOS Mojave 10.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/kb/HT209139mitrex_refsource_MISC
- support.apple.com/kb/HT209193mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.