An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Jun 4, 2018 | May 29, 2018 |
| Apple Safari | — | Upgrade to Apple Safari version 11.1.1Uninstall Apple Safari on Windows | Jun 4, 2018 | Jun 4, 2018 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Jun 8, 2018 |
| Gentoo Linux | — | Upgrade net-libs/webkit-gtk. | Aug 23, 2018 | Jun 8, 2018 |
| Oracle Solaris | — | Upgrade x11/library/libx11 to version 1.6.5-11.4.3.0.1.1.0 on Solaris 11.4Upgrade communication/im/pidgin to version 2.12.0-11.4.3.0.1.1.0 on Solaris 11.4Upgrade library/desktop/webkitgtk4 to version 2.20.5-11.4.3.0.1.1.0 on Solaris 11.4Upgrade library/audio/taglib to version 1.11.1-11.4.3.0.1.1.0 on Solaris 11.4 | Nov 19, 2018 | Jun 8, 2018 |
| Ubuntu | — | Upgrade webkit2gtk | Nov 19, 2024 | Jun 8, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub