CVE-2018-4277: Apple iPhone OS

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.

Affected products

  • Apple iPhone OS: before 11.4.1 (fixed in 11.4.1)
  • Apple Mac OS X: before 10.13.6 (fixed in 10.13.6)
  • Apple Safari: before 11.1.1 (fixed in 11.1.1)
  • Apple tvOS: before 11.4.1 (fixed in 11.4.1)
  • Apple watchOS: before 4.3.2 (fixed in 4.3.2)

Published 2019-01-11. Last modified 2026-06-17.