CVE-2018-4237

HIGH EXPLOITED

Mac OS X libxpc MITM Privilege Escalation

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2018-4237 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Metasploit, saelo, including a Metasploit module exploits/osx/local/libxpc_mitm_ssudo.

AI-analyzed exploit summary This Metasploit module exploits CVE-2018-4237, a privilege escalation vulnerability in macOS libxpc (<= 10.13.3). It manipulates the bootstrap port to intercept communication between sudo and opendirectoryd, allowing password validation bypass.

Description

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "libxpc" component. It allows attackers to gain privileges via a crafted app that leverages a logic error.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalmacos
https://www.exploit-db.com/exploits/45916

This Metasploit module exploits CVE-2018-4237, a privilege escalation vulnerability in macOS libxpc (<= 10.13.3). It manipulates the bootstrap port to intercept communication between sudo and opendirectoryd, allowing password validation bypass.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: macOS <= 10.13.3
No auth needed
Prerequisites: Non-root session on vulnerable macOS · Writable directory (default: /tmp)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by saelo · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/libxpc_mitm_ssudo.rb

This Metasploit module exploits CVE-2018-4237, a privilege escalation vulnerability in macOS libxpc (versions <= 10.13.3). It leverages a MITM attack on the bootstrap port to intercept and modify communications between sudo and opendirectoryd, allowing arbitrary command execution as root.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: macOS libxpc (macOS <= 10.13.3)
No auth needed
Prerequisites: Local access to a vulnerable macOS system · Non-root user session
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208850
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208851
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041027
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208848
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208849
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45916/

Scores

CVSS v3 7.8
EPSS 0.6295
EPSS Percentile 98.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-07-30
Status published
Products (4)
apple/iphone_os < 11.4
apple/mac_os_x < 10.13.5
apple/tvos < 11.4
apple/watchos < 4.3.1
Published Jun 08, 2018
Tracked Since Feb 18, 2026