CVE-2018-4131

MEDIUM

Description

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "WindowServer" component. It allows attackers to bypass the Secure Input Mode protection mechanism, and log keystrokes of arbitrary apps, via a crafted app that scans key states.

References

http://www.securityfocus.com/bid/103581

http://www.securitytracker.com/id/1040604

http://www.securitytracker.com/id/1040608

https://support.apple.com/HT208692

https://support.apple.com/HT208693

https://twitter.com/boastr_net/status/979624397664333824

Details

Source: MITRE

Published: 2018-04-03

Updated: 2018-05-04

Type: CWE-254

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH