CVE-2018-4206
HIGHApple tvOS < 11.4 - Remote Code Execution via Privileged Port Name Replacement
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-4206. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a mach port replacement vulnerability in ReportCrash on macOS 10.13.3 by sending a malformed mach_exception_raise_state_identity message, causing a UREF drop on privileged ports. It demonstrates the bug by destroying ReportCrash's send right to logd.
Description
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app that replaces a privileged port name.
Exploits (1)
This PoC exploits a mach port replacement vulnerability in ReportCrash on macOS 10.13.3 by sending a malformed mach_exception_raise_state_identity message, causing a UREF drop on privileged ports. It demonstrates the bug by destroying ReportCrash's send right to logd.
References (9)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H