CVE-2018-4277: Apple iPhone OS
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
Affected products
- Apple iPhone OS: before 11.4.1 (fixed in 11.4.1)
- Apple Mac OS X: before 10.13.6 (fixed in 10.13.6)
- Apple Safari: before 11.1.1 (fixed in 11.1.1)
- Apple tvOS: before 11.4.1 (fixed in 11.4.1)
- Apple watchOS: before 4.3.2 (fixed in 4.3.2)
Published 2019-01-11. Last modified 2026-06-17.