Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-4343. PoCs published by bazad.
AI-analyzed exploit summary This PoC exploits a use-after-free vulnerability in the `com.apple.GSSCred` XPC service on macOS and iOS. By sending a crafted XPC message with identical source and destination UUIDs, it triggers a logic error in the `do_Move` function, leading to a crash or potential code execution.
Description
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
Exploits (1)
This PoC exploits a use-after-free vulnerability in the `com.apple.GSSCred` XPC service on macOS and iOS. By sending a crafted XPC message with identical source and destination UUIDs, it triggers a logic error in the `do_Move` function, leading to a crash or potential code execution.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H