Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-4416. PoCs published by Google Security Research, erupmi.
AI-analyzed exploit summary This PoC exploits a type confusion vulnerability in JavaScriptCore (CVE-2018-4416) by manipulating structure IDs during a for-in loop, leading to arbitrary memory access. The exploit triggers a garbage collection to free a structure ID and then reuses it to achieve type confusion.
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
Exploits (2)
This PoC exploits a type confusion vulnerability in JavaScriptCore (CVE-2018-4416) by manipulating structure IDs during a for-in loop, leading to arbitrary memory access. The exploit triggers a garbage collection to free a structure ID and then reuses it to achieve type confusion.
This exploit leverages a type confusion vulnerability in JavaScriptCore (CVE-2018-4416) to achieve arbitrary memory read/write and execute shellcode. It manipulates JIT-compiled functions and object prototypes to bypass security checks and overwrite executable memory regions.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H