CVE-2018-4443

HIGH EXPLOITED

Safari < 12.0.2 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-4443 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Google Security Research.

AI-analyzed exploit summary The exploit leverages a type confusion vulnerability in JavaScriptCore (CVE-2018-4443) where `structure->indexingType()` incorrectly masks the CopyOnWrite flag, allowing writes to immutable butterflies. This leads to a use-after-free (UaF) condition, demonstrated via two PoCs manipulating array structures.

Description

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · htmldosmultiple
https://www.exploit-db.com/exploits/46071

The exploit leverages a type confusion vulnerability in JavaScriptCore (CVE-2018-4443) where `structure->indexingType()` incorrectly masks the CopyOnWrite flag, allowing writes to immutable butterflies. This leads to a use-after-free (UaF) condition, demonstrated via two PoCs manipulating array structures.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WebKit JavaScriptCore (Safari, other WebKit-based browsers)
No auth needed
Prerequisites: Target must run JavaScriptCore with `--useConcurrentJIT=false`
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209343
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209342
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209340
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209344
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209346
Vendor Advisory x_refsource_misc
https://support.apple.com/kb/HT209345

Scores

CVSS v3 8.8
EPSS 0.1867
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-05-06
CWE
CWE-119
Status published
Products (6)
apple/icloud < 7.9
apple/iphone_os < 12.1.1
apple/itunes < 12.9.2
apple/safari < 12.0.2
apple/tvos < 12.1.1
apple/watchos < 5.1.2
Published Apr 03, 2019
Tracked Since Feb 18, 2026