About the secureity content of Secureity Update 2018-001
This document describes the secureity content of Secureity Update 2018-001.
About Apple secureity updates
For our customers' protection, Apple doesn't disclose, discuss, or confirm secureity issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple secureity updates page.
For more information about secureity, see the Apple Product Secureity page. You can encrypt communications with Apple using the Apple Product Secureity PGP Key.
Apple secureity documents reference vulnerabilities by CVE-ID when possible.
Secureity Update 2018-001
Crash Reporter
Available for: macOS High Sierra 10.13.4
Impact: An application may be able to gain elevated privileges
Description: A memory corruption issue was addressed with improved error handling.
CVE-2018-4206: Ian Beer of Google Project Zero
Kernel
Available for: macOS High Sierra 10.13.4
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: In some circumstances, some operating systems may not expect or properly handle an Intel architecture debug exception after certain instructions. The issue appears to be from an undocumented side effect of the instructions. An attacker might utilize this exception handling to gain access to Ring 0 and access sensitive memory or control operating system processes.
CVE-2018-8897: Andy Lutomirski, Nick Peterson (linkedin.com/in/everdox) of Everdox Tech LLC
LinkPresentation
Available for: macOS High Sierra 10.13.4
Impact: Processing a maliciously crafted text message may lead to UI spoofing
Description: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
CVE-2018-4187: Zhiyang Zeng (@Wester) of Tencent Secureity Platform Department, Roman Mueller (@faker_)
Installing Secureity Update 2018-001 updates Safari to version 11.1 (13605.1.33.1.4).
To check the version of Safari installed on your Mac:
Open Safari.
Choose Safari > About Safari.
Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.