logo

CVE-2018-4282: Out-of-bounds read vulnerability in AppleT8015PPM.kext

ID: 91aa97bc-ebaf-51a7-8f9e-bce4a338dc3c

STIX ID: report--91aa97bc-ebaf-51a7-8f9e-bce4a338dc3c

Feed Name: Zimperium Blog

Threat Score
45/100

Date Published: 2018-10-23

Date Updated: 2026-05-01

...
...

This report describes a kernel-level read-out-of-bounds vulnerability (CVE-2018-4282) in AppleT8015PPM.kext that can result in reading unintended kernel memory when handling a dictionary input (selector 13, sPushTelemetry). The bug was discovered in May 2018, responsibly disclosed to Apple, and fixed in iOS 11.4.1 on 2018-07-09; no active exploitation is reported in the document.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.