vciy

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari: 20 records in one advisory

20 records announced together, published 2018-04-03, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://support.apple.com/HT208693. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

3 of 20 records name something of its own. For the other 17, held sources say the same thing about each.

What this page does not cover

This batch is 20 of the 46 records that cite the same advisory. The other 26 are different findings announced alongside it.

None of those 26 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2018-4101no title held
CVE-2018-4113javascriptcore function trigger assertion
CVE-2018-4114no title held
CVE-2018-4117fetch api same origin
CVE-2018-4118no title held
CVE-2018-4119no title held
CVE-2018-4120no title held
CVE-2018-4121no title held
CVE-2018-4122no title held
CVE-2018-4125no title held
CVE-2018-4127no title held
CVE-2018-4128no title held
CVE-2018-4129no title held
CVE-2018-4130no title held
CVE-2018-4137login autofill autofilled lack
CVE-2018-4146no title held
CVE-2018-4161no title held
CVE-2018-4162no title held
CVE-2018-4163no title held
CVE-2018-4165no title held

20 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.