Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-4197. PoCs published by Google Security Research.
AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2018-4197, a use-after-free vulnerability in WebKit. The PoC triggers the vulnerability by manipulating DOM elements and selections, leading to a heap-use-after-free condition as confirmed by the AddressSanitizer log.
Description
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Exploits (1)
This is a proof-of-concept exploit for CVE-2018-4197, a use-after-free vulnerability in WebKit. The PoC triggers the vulnerability by manipulating DOM elements and selections, leading to a heap-use-after-free condition as confirmed by the AddressSanitizer log.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H