CVE-2018-4390: Apple iPhone OS

Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.

Affected products

  • Apple iPhone OS: before 12.1 (fixed in 12.1)
  • Apple Mac OS X: from 10.13, before 10.13.1 (fixed in 10.13.1)
  • Apple watchOS: before 4.3 (fixed in 4.3)

Published 2020-10-27. Last modified 2026-06-17.