CVE-2018-4397: Apple Support

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.

Affected products

  • Apple Apple Support: before 2.4 (fixed in 2.4)

Published 2019-04-03. Last modified 2026-06-17.