CVE-2018-4280 is a memory corruption vulnerability affecting Apple operating systems, including iOS versions prior to 11.4.1, macOS High Sierra prior to 10.13.6, tvOS prior to 11.4.1, and watchOS prior to 4.3.2. The vulnerability arises from improper memory handling, which could potentially allow an attacker to corrupt memory and execute arbitrary code or cause a denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a fully operational local privilege escalation exploit for macOS, specifically targeting CVE-2018-4280, a port replacement vulnerability in launchd. The exploit is implemented in C, with supporting bash scripts for automating payload delivery and shell access. The main exploit works by sending crafted Mach exception messages to launchd, causing it to deallocate its send right to a targeted service port (notably com.apple.CoreServices.coreservicesd). The attacker then impersonates this service, intercepts privileged Mach messages, and leverages the sysdiagnose process (which has the task_for_pid-allow entitlement) to gain arbitrary code execution as root. The exploit can execute arbitrary system commands as root or inject a dynamic library into any process, effectively bypassing System Integrity Protection (SIP). The repository includes example scripts to automate the creation of a SUID root shell and to spawn a root shell with SIP bypass. The code is well-documented, with a detailed README explaining the vulnerability, exploitation strategy, and usage instructions. The attack vector is local, requiring code execution on the target system, and the exploit is tested on macOS 10.13.5. Notable endpoints include the SUID shell at /private/var/suid-sh, the SIP-protected file /System/exploit-success, and the launchd service com.apple.CoreServices.coreservicesd.
This repository implements a sophisticated local privilege escalation and sandbox escape exploit for iOS 11.2.6 (and earlier versions up to iOS 11.4.0), targeting CVE-2018-4280, a Mach port replacement vulnerability in launchd. The exploit chain involves several stages: 1. **Triggering the launchd Mach port over-deallocation bug** to impersonate system services. 2. **Escaping the application sandbox** by gaining code execution in the unsandboxed, root-owned ReportCrash process, which has the powerful task_for_pid-allow entitlement. 3. **Bypassing AMFI (Apple's code signing enforcement)** by installing a custom daemon (amfidupe) that manipulates the amfid process, allowing unsigned or pseudo-signed code to run with platform binary privileges. 4. **Spawning a payload (blanket_payload)** that sets up a bind shell on TCP port 4242, providing remote root shell access to the device. The exploit is implemented in C and Objective-C, with a modular structure: the main exploit logic is in the `blanket` directory, the AMFI bypass in `amfidupe`, and the payload in `blanket_payload`. The exploit requires building and deploying a custom app (with appropriate entitlements) to the target device, and is operational (not just a POC), as it provides a working root shell if successful. The exploit also includes code for restoring system state after exploitation and for handling various Mach services involved in the privilege escalation chain. Notable endpoints include the amfid binary (`/usr/libexec/amfid`), the ReportCrash and CARenderServer Mach services, and the bind shell on port 4242. The exploit is highly advanced, leveraging deep knowledge of iOS internals, Mach IPC, and code signing mechanisms.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.