CVE-2018-4121
HIGHSafari < 11.1 - Remote Code Execution via WebKit Memory Corruption
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2018-4121. PoCs published by Google Security Research, FSecureLABS, jezzus.
AI-analyzed exploit summary The exploit leverages a WebAssembly parsing vulnerability in Safari where custom sections bypass ordering checks, leading to potential overflows and type confusion. The provided PoC includes a crafted HTML and WASM file that triggers a crash in Safari.
Description
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Exploits (5)
The exploit leverages a WebAssembly parsing vulnerability in Safari where custom sections bypass ordering checks, leading to potential overflows and type confusion. The provided PoC includes a crafted HTML and WASM file that triggers a crash in Safari.
This is a proof-of-concept exploit for CVE-2018-4121, targeting a WebAssembly (Wasm) vulnerability in Safari 11.0.3 on macOS 10.13.3. The exploit leverages heap spraying and memory corruption to achieve remote code execution (RCE) by overflowing a function section in Wasm.
This is a proof-of-concept exploit for CVE-2018-4121, targeting a WebAssembly (Wasm) vulnerability in Safari 11.0.3 on macOS 10.13.3. The exploit leverages heap spraying and memory corruption to achieve remote code execution (RCE) by overflowing a function section in Wasm.
This is a proof-of-concept exploit for CVE-2018-4121, targeting a WebAssembly (Wasm) vulnerability in Safari 11.0.3 on macOS 10.13.3. The exploit leverages heap spraying and memory corruption to achieve remote code execution (RCE).
This repository contains a functional proof-of-concept exploit for CVE-2018-4121, targeting Safari 11.0.3 on macOS 10.13.3. The exploit leverages a WebAssembly (Wasm) section vulnerability to achieve remote code execution (RCE) via heap manipulation and vtable corruption.
References (10)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H