CVE-2018-4331

CRITICAL

iPhone OS < 12.0 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-4331. PoCs published by bazad.

AI-analyzed exploit summary This is a working proof-of-concept exploit for CVE-2018-4331, targeting a race condition in GSSCred on macOS. The exploit uses JOP (Jump-Oriented Programming) techniques to achieve arbitrary code execution by reusing existing code fragments in the dyld shared cache.

Description

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

Exploits (1)

nomisec WORKING POC 24 stars
by bazad · poc
https://github.com/bazad/gsscred-race

This is a working proof-of-concept exploit for CVE-2018-4331, targeting a race condition in GSSCred on macOS. The exploit uses JOP (Jump-Oriented Programming) techniques to achieve arbitrary code execution by reusing existing code fragments in the dyld shared cache.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: macOS GSSCred (likely affecting macOS High Sierra and earlier)
No auth needed
Prerequisites: Local access to a vulnerable macOS system · Compilation of the exploit code for the target architecture
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209107
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209193
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209106
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209139
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209108

Scores

CVSS v3 9.8
EPSS 0.0436
EPSS Percentile 90.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (4)
apple/iphone_os < 12.0
apple/mac_os_x < 10.14
apple/tvos < 12
apple/watchos < 5.0
Published Apr 03, 2019
Tracked Since Feb 18, 2026