VYPR
Unrated severityNVD Advisory· Published Apr 3, 2019· Updated Aug 5, 2024

CVE-2018-4347

CVE-2018-4347

Description

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free in multiple Apple platforms allows a local app to disclose persistent account identifiers or execute arbitrary code with system privileges.

Vulnerability

A use-after-free vulnerability exists in the kernel extension handling of multiple Apple platforms, including iOS prior to 12, macOS Mojave prior to 10.14, tvOS prior to 12, watchOS prior to 5, iTunes prior to 12.9 for Windows, and iCloud for Windows prior to 7.7 [1][2][3][4]. The issue was addressed with improved memory management.

Exploitation

An attacker must have the ability to run a locally installed application on the affected device. No other special network position or user interaction beyond launching the malicious app is required [1][2][3][4]. The exact exploitation steps are not disclosed in the available references.

Impact

Depending on the platform, successful exploitation can allow a local app to read a persistent account identifier (iOS, tvOS) or potentially execute arbitrary code with system privileges (watchOS) [1][3][4]. The macOS advisory links to Bluetooth-related components, though the exact impact for macOS is not fully detailed [2].

Mitigation

Apple released fixes in iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, and iCloud for Windows 7.7 on September 17, 2018 (September 24, 2018 for macOS) [1][2][3][4]. Users should update to the latest available versions. No workarounds were provided in the advisories.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.