VulnerabilityModified
CVE-2018-4278
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin.
MEDIUM 4.3EPSS 2.28%
Does this matter?
Lower severity and a low EPSS score (2.28%). Track it; it rarely justifies an emergency change on its own.
Description
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- apple/safari · apple/iphone os · apple/tvos · apple/icloud · apple/itunes · canonical/ubuntu linux
- Source
- product-security@apple.com
References
- http://www.securitytracker.com/id/1041232Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201808-04Third Party Advisory
- https://support.apple.com/HT208932Vendor Advisory
- https://support.apple.com/HT208933%2C
- https://support.apple.com/HT208934%2C
- https://support.apple.com/HT208936%2C
- https://support.apple.com/HT208938%2C
- https://usn.ubuntu.com/3743-1/Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/146479Third Party Advisory
- http://www.securitytracker.com/id/1041232Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201808-04Third Party Advisory
- https://support.apple.com/HT208932Vendor Advisory
- https://support.apple.com/HT208933%2C
- https://support.apple.com/HT208934%2C
- https://support.apple.com/HT208936%2C
- https://support.apple.com/HT208938%2C
- https://usn.ubuntu.com/3743-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.