CVE-2018-4407
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
- Published
- Apr 3, 2019
- Updated
- Aug 5, 2024
- Assigning CNA
- apple
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 97.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
Sources
15ios 缓冲区溢出exp
Crashes any macOS High Sierra or iOS 11 device that is on the same WiFi network
- AppleDOSPoC
Messing Apple devices on the network with CVE-2018-4407 (heap overflow in bad packet handling)
A buffer overflow vulnerability in the XNU kernel's ICMP error code causes IOS devices to crash (laptops and mobiles).
- CVE-2018-4407Exploit
IOS/MAC Denial-Of-Service [POC/EXPLOIT FOR MASSIVE ATTACK TO IOS/MAC IN NETWORK]
Node.js PoC exploit code for CVE-2018-4407
- CVE-2018-4407Exploit
Exploit code for CVE-2018-4407
Crash macOS and iOS devices with one packet
- CVE-2018-4407Exploit
CVE-2018-4407 IOS/macOS kernel crash
POC: Heap buffer overflow in the networking code in the XNU operating system kernel
Kernel crash caused by out-of-bounds write in Apple's ICMP packet-handling code (CVE-2018-4407)
iOS 12 / OS X Remote Kernel Heap Overflow (CVE-2018-4407) POC
Exploit for CVE-2018-4407-Memory Corruption
CVE-2018-4407 概述與實現
- CVE-2018-4407-iOS-exploitExploit
CVE-2018-4407,iOS exploit
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.