{"api_version":"1","generated_at":"2026-07-23T07:06:23+00:00","cve":"CVE-2018-4095","urls":{"html":"https://cve.report/CVE-2018-4095","api":"https://cve.report/api/cve/CVE-2018-4095.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-4095","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-4095"},"summary":{"title":"CVE-2018-4095","description":"An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the \"Core Bluetooth\" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2018-04-03 06:29:00","updated_at":"2018-04-27 18:18:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/102774","name":"102774","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Apple iOS/tvOS/watchOS Memory Corruption Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1040265","name":"1040265","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple iOS Multiple Flaws Let Remote Users Deny Service, Execute Arbitrary Code, and Bypass Security Restrictions and Let Applications Access Restricted Memory and Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT208462","name":"https://support.apple.com/HT208462","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of tvOS 11.2.5 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT208464","name":"https://support.apple.com/HT208464","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of watchOS 4.2.2 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.zimperium.com/cve-2018-4087-poc-escaping-sandbox-misleading-bluetoothd/","name":"https://blog.zimperium.com/cve-2018-4087-poc-escaping-sandbox-misleading-bluetoothd/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"CVE-2018-4087 PoC Escape sandbox by misleading bluetoothd","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT208463","name":"https://support.apple.com/HT208463","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of iOS 11.2.5 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-4095","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-4095","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"apple_tv","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"apple_tv","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"watchos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4095","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"watchos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2018-4095","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the \"Core Bluetooth\" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://support.apple.com/HT208462","refsource":"CONFIRM","url":"https://support.apple.com/HT208462"},{"name":"1040265","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040265"},{"name":"102774","refsource":"BID","url":"http://www.securityfocus.com/bid/102774"},{"name":"https://support.apple.com/HT208464","refsource":"CONFIRM","url":"https://support.apple.com/HT208464"},{"name":"https://blog.zimperium.com/cve-2018-4087-poc-escaping-sandbox-misleading-bluetoothd/","refsource":"MISC","url":"https://blog.zimperium.com/cve-2018-4087-poc-escaping-sandbox-misleading-bluetoothd/"},{"name":"https://support.apple.com/HT208463","refsource":"CONFIRM","url":"https://support.apple.com/HT208463"}]}},"nvd":{"publishedDate":"2018-04-03 06:29:00","lastModifiedDate":"2018-04-27 18:18:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"11.2.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:apple_tv:*:*:*:*:*:*:*:*","versionEndExcluding":"11.2.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*","versionEndExcluding":"4.2.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"4095","Ordinal":"120009","Title":"CVE-2018-4095","CVE":"CVE-2018-4095","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"4095","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the \"Core Bluetooth\" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"4095","Ordinal":"2","NoteData":"2018-04-03","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"4095","Ordinal":"3","NoteData":"2018-04-03","Type":"Other","Title":"Modified"}]}}}