CVE-2018-4124
Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2.6, las versiones de macOS anteriores a la 10.13.3 Supplemental Update, las versiones de tvOS anteriores a la 11.2.6 y las versiones de watchOS anteriores a la 4.2.3 se han visto afectadas. El problema afecta al componente "CoreText". Permite que atacantes remotos provoquen una denegación de servicio (corrupción de memoria y cierre inesperado del sistema) o, posiblemente, otro impacto no especificado mediante una cadena manipulada que contenga un carácter Telugu determinado.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.85%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Prueba de concepto en GitHub (no verificada) · Lista de pruebas de concepto en GitHub
⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.
Tecnologías afectadas (4)
CWE
- CWE-119
Referencias
- http://www.securitytracker.com/id/1040396
- https://nakedsecurity.sophos.com/2018/02/20/apple-fixes-that-1-character-to-crash-your-mac-and-iphone-bug/
- https://support.apple.com/HT208534
- https://support.apple.com/HT208535
- https://support.apple.com/HT208536
- https://support.apple.com/HT208537
- http://www.securitytracker.com/id/1040396
- https://nakedsecurity.sophos.com/2018/02/20/apple-fixes-that-1-character-to-crash-your-mac-and-iphone-bug/
- https://support.apple.com/HT208534
- https://support.apple.com/HT208535
- https://support.apple.com/HT208536
- https://support.apple.com/HT208537
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-4124",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:C",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 8.5,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-04-03T06:29:05.453",
"references": [
{
"url": "http://www.securitytracker.com/id/1040396",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "product-security@apple.com"
},
{
"url": "https://nakedsecurity.sophos.com/2018/02/20/apple-fixes-that-1-character-to-crash-your-mac-and-iphone-bug/",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT208534",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT208535",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT208536",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT208537",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.securitytracker.com/id/1040396",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nakedsecurity.sophos.com/2018/02/20/apple-fixes-that-1-character-to-crash-your-mac-and-iphone-bug/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT208534",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT208535",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT208536",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT208537",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the \"CoreText\" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.2.6, las versiones de macOS anteriores a la 10.13.3 Supplemental Update, las versiones de tvOS anteriores a la 11.2.6 y las versiones de watchOS anteriores a la 4.2.3 se han visto afectadas. El problema afecta al componente \"CoreText\". Permite que atacantes remotos provoquen una denegación de servicio (corrupción de memoria y cierre inesperado del sistema) o, posiblemente, otro impacto no especificado mediante una cadena manipulada que contenga un carácter Telugu determinado."
}
],
"lastModified": "2026-06-17T01:58:24.580",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23FFC8EF-7F1A-42AE-9047-6FD0099FAB55",
"versionEndExcluding": "11.2.6"
},
{
"criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C8076C1-E629-4293-932D-937DF1218C76",
"versionEndExcluding": "10.13.3"
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE67D56C-0580-4992-B8A4-817BE6524042",
"versionEndExcluding": "11.2.6"
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5233C45-C04F-4003-AED7-991139BCDCD0",
"versionEndExcluding": "4.2.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}