CVE-2018-4150 is a memory corruption vulnerability in the Kernel component of multiple Apple operating systems, including iOS before 11.3, macOS before 10.13.4, tvOS before 11.3, and watchOS before 4.3. The vulnerability can be triggered by a crafted application, allowing an attacker to execute arbitrary code with kernel privileges or cause a denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single C proof-of-concept exploit (CVE-2018-4150.c) and a brief README. The exploit targets a race condition in Apple's BPF (Berkeley Packet Filter) device implementation, specifically by racing the BIOCSDLT and BIOCSBLEN ioctls to cause a buffer overflow. The code is designed to work on iOS up to version 11.2.6 and likely affects macOS as well. The exploit works by opening /dev/bpf3, setting up a raw IPv6 socket, and using multiple threads to race the buffer length setting, eventually allowing the sending of an oversized packet to the loopback address. The repository is a functional proof-of-concept and does not include a weaponized payload or privilege escalation code, but demonstrates the vulnerability and its exploitation. The main entry point is CVE-2018-4150.c, written in C, and the attack vector is local, requiring access to the BPF device and raw sockets.
This repository contains a single exploit file (exploit.m) and a license. The exploit targets CVE-2018-4150, a race condition in the BPF device on macOS and iOS (up to iOS 11.2.6, pre-iPhone 7). The exploit is written in Objective-C and is designed to be run locally on a vulnerable device. It works by racing two threads to exploit a bad locking bug in the BPF device, causing a heap overflow. The exploit then sends a crafted packet to the default router IP (192.168.0.1) to trigger the overflow, leaks the kernel base address, and provides an early kernel read primitive. The code is a proof-of-concept and does not provide a full privilege escalation or shell, but it lays the groundwork for further exploitation. The repository is well-commented, explaining each step of the exploit process, and is intended for research and development of further kernel exploits.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.