logo

CVE-2018-4109: Overwriting kernel memory with a few video packets

ID: 5c8696f8-f240-5348-b0ec-ff9177a70eeb

STIX ID: report--5c8696f8-f240-5348-b0ec-ff9177a70eeb

Feed Name: Zimperium Blog

Threat Score
50/100

Date Published: 2018-11-12

Date Updated: 2026-05-01

...
...

This write-up documents CVE-2018-4109: a kernel-level buffer-overflow primitive stemming from an IOSurface plane offset sign mismatch and a tile-decoding flaw in AppleD5500.kext (video decoder). The researcher shows how carefully crafted video bitstreams and use of mediaserverd allow a sandboxed app to trigger a memset-based overwrite (controlling offset and length), enabling powerful kernel memory corruption; the issue was responsibly disclosed to Apple and patched in January 2018.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.