Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed

Share and earn Cybytes
Facebook Twitter LinkedIn Email

A researcher has disclosed a buffer overflow vulnerability in Apple’s XNU operating system kernel that allows attackers on a local network to reboot Apple’s iOS and macOS devices and could potentially lead to remote code execution.


On October 30, researcher Kevin Backhouse of Semmle published a blog on his discovery of a buffer overflow vulnerability in Apple’s XNU operating system kernel (CVE-2018-4407). Specifically, the vulnerability exists in the networking code for XNU for how packets are handled. The vulnerability affects OS X, macOS and iOS devices. Backhouse released a proof of concept (PoC) video demonstrating how this vulnerability can be used to crash macOS and iOS devices on a local network.

The PoC has been withheld to allow time for Apple users to upgrade their devices.

Impact assessment

According to Backhouse, this vulnerability affects iOS devices running iOS 11 and earlier. It also affects legacy devices running Apple’s OS X operating system from El Capitan and earlier, as well as macOS Sierra and High Sierra. The vulnerability was reported to Apple in August 2018 and it had been patched in iOS 12 and macOS Mojave.

Vulnerability details

This vulnerability allows a local network attacker to send a specially crafted Internet Protocol (IP) packet to unsuspecting Apple users that triggers a device reboot (or denial of service). While not demonstrated, Backhouse reports that this vulnerability could lead to remote code execution because an attacker can “control the size and content of the heap buffer overflow.” Additionally, he asserts, “the vulnerability is in such a fundamental part of the networking code that anti-virus software will not protect you[…] It also doesn’t matter what software you are running on the device – the malicious packet will still trigger the vulnerability even if you don’t have any ports open.”

Urgently required actions

Apple users should upgrade to the latest versions of their respective operating systems. In this case, both iOS 12 and macOS Mojave (10.14) have addressed this vulnerability. Apple has also addressed this vulnerability in macOS Sierra and macOS High Sierra.

Identifying affected systems

A list of Tenable plugins to identify this vulnerability will appear here as they’re released.

Get more information

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

Share this post and earn Cybytes
Facebook Twitter LinkedIn Email
About Tenable
Tenable™, Inc. is the Cyber Exposure company. Over 24,000 organizations of all sizes around the globe rely on Tenable to manage and measure their modern attack surface to accurately understand and reduce cyber risk. As the creator of Nessus®, Tenable built its platform from the ground up to deeply understand assets, networks and vulnerabilities, extending this knowledge and expertise into Tenable.io™ to deliver the world’s first platform to provide live visibility into any asset on any computing platform. Tenable customers include over 50 percent of the Fortune 500, large government agencies and organizations across the private and public sectors. Learn more at tenable.com.
Promoted Content
Five Steps to Building a Successful Vulnerability Management Program
Is your vulnerability management program struggling? Despite proven technology solutions and the best efforts of IT teams, unresolved vulnerabilities remain an ongoing source of friction and frustration in many organizations. Regardless of how many vulnerabilities are fixed, there will always be vulnerabilities that can’t easily be remediated – and too often, finger-pointing between IT teams and business groups can ensue.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play

Support Cybrary

Donate Here to Get This Month's Donor Badge

Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?