CVE-2018-4407 is an Apple kernel vulnerability affecting versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, and watchOS 5. Apple describes it as a memory corruption issue in the kernel that was addressed through improved validation. The available vendor description indicates that malformed or unexpected network traffic handled by the affected kernel code could trigger memory corruption, creating a path to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2018-4407, a vulnerability in the IP options handling of Apple's macOS and iOS network stack that can lead to a system crash. The main exploit is implemented in 'send_badopt.go', a Go program that sends a continuous stream of custom-crafted IPv4 packets with invalid IP options to a specified victim IP address. The attacker must set the source and destination IPs in the code before running the exploit. The repository also includes 'scripts/listen.go', a Go program for listening to ICMP packets (useful for debugging or monitoring network traffic), and 'scripts/ip_stats.sh', a Bash script to extract and display IP stack statistics from the kernel, which can help verify if the exploit is triggering errors. The exploit targets Apple macOS and iOS devices running versions prior to late 2018, and if successful, will crash the victim's machine. No hardcoded external endpoints are present; the user must specify the relevant IP addresses.
This repository contains a Python proof-of-concept exploit for CVE-2018-4407, a vulnerability in the Apple iOS and macOS kernel that allows remote attackers to crash the device via specially crafted IP packets. The main file, CVE_2018_4407.py, accepts an IP address or CIDR range as input, scans for live hosts, and sends malformed IP packets with custom IP options to TCP port 2323 on each target. The exploit leverages the Scapy library for packet crafting and can be run in parallel threads for efficiency. The README provides usage instructions and suggests using nmap to discover potential targets (e.g., iPhones on a local network). The exploit's primary capability is to cause a denial of service (kernel crash) on vulnerable Apple devices accessible over the network. No hardcoded IPs or domains are present, but the attack targets TCP port 2323 on the specified hosts.
This repository contains a Python-based exploit for CVE-2018-4407, a heap buffer overflow vulnerability in the XNU kernel used by Apple iOS and macOS devices. The exploit is implemented in 'exploit.py', which uses the nmap library to scan a target IP or network range for live hosts, then sends specially crafted IP packets with oversized options fields to each discovered host using scapy. The attack is designed to trigger a buffer overflow in the target's networking stack, resulting in a Denial of Service (DoS) condition. The exploit is configurable via command-line arguments, allowing the user to specify the target range, source IP, and the number of payload iterations. The repository also includes a README with usage instructions, a requirements.txt listing Python dependencies, and standard project files (.gitignore, LICENSE). No hardcoded IP addresses or domains are present; all targets are user-supplied at runtime. The exploit is operational and can be used to demonstrate or test the vulnerability on affected Apple devices.
This repository contains a proof-of-concept (PoC) exploit for CVE-2018-4407, a heap overflow vulnerability in Apple's XNU kernel affecting iOS (up to version 11) and macOS (up to High Sierra 10.13.6, Sierra 10.12.6, and El Capitan and earlier). The exploit is implemented in a single Python script ('appledos.py') that uses the 'scapy' library to craft and send malformed TCP/IP packets with oversized header options to a specified IP address or subnet. When a vulnerable device receives such a packet and attempts to generate an ICMP error message, the malformed options cause a heap overflow, crashing the device (denial of service). The script supports targeting individual IPs or subnets, continuous attack mode, configurable destination port, and multi-threaded operation. The README provides detailed usage instructions and warnings. The only code file is 'appledos.py'; the other files are a license and documentation. No hardcoded external network endpoints are present, but the script is designed to target user-specified IP addresses on the local network.
This repository provides a proof-of-concept (PoC) exploit for CVE-2018-4407, a heap buffer overflow vulnerability in Apple's XNU kernel affecting iOS and macOS devices. The exploit is implemented in Python (exploit.py) and is designed to be run on a Linux system with root privileges. It uses the scapy and nmap libraries to scan the local network for hosts, then sends specially crafted IP/TCP packets to each discovered host. The payload leverages the vulnerability to cause a kernel panic and reboot on affected Apple devices. The repository includes a simple installer script (install/install.sh) to set up dependencies, and a requirements file for Python packages. The README provides background on the vulnerability and usage instructions. No hardcoded IP addresses or external network endpoints are present; the exploit targets devices on the local network as discovered by nmap. The code is a functional PoC and does not provide a weaponized or highly automated attack, but demonstrates the vulnerability's impact.
This repository contains a proof-of-concept exploit for CVE-2018-4407, a vulnerability in the Apple XNU kernel affecting iOS 11 and earlier, macOS High Sierra 10.13.6 and earlier, macOS Sierra 10.12.6 and earlier, and OS X El Capitan and earlier. The exploit is implemented in a single Python script ('check_icmp_dos.py') that uses the 'scapy' library to craft and send malformed IP packets with invalid options to a specified target IP address. The malformed packets exploit a lack of size checking in the kernel's ICMP packet parsing, potentially causing a kernel crash (denial of service) on vulnerable Apple devices. The script must be run with root privileges and requires the target IP as an argument. The README provides background on the vulnerability, affected devices, and references for further reading. No hardcoded endpoints are present; the target is specified by the user at runtime.
This repository contains a Node.js proof-of-concept exploit for CVE-2018-4407, a remote kernel heap overflow vulnerability affecting Apple iOS (up to version 11) and some versions of OS X. The main exploit logic is implemented in 'attack.js', which constructs and sends custom raw IP/TCP packets with malformed options to a user-specified target IP address. The exploit leverages the 'raw-socket' and 'ip' Node.js modules to craft and transmit these packets. When run (with 'node attack.js <target_ip>'), the script repeatedly sends the malicious packets to TCP port 2323 on the target, potentially causing a kernel crash and denial of service. The repository is structured with a single main exploit file, a package.json for dependencies, and supporting documentation. No hardcoded IPs or domains are present; the target is specified at runtime. The exploit is a functional PoC and does not provide post-exploitation capabilities or a customizable payload beyond the crafted packet.
This repository contains a proof-of-concept (POC) exploit for CVE-2018-4407, a remote kernel heap overflow vulnerability affecting Apple iOS (<=11), macOS High Sierra (<=10.13.6), macOS Sierra (<=10.12.6), and OS X El Capitan and earlier. The exploit consists of a single Python script ('check_icmp_dos.py') that uses the Scapy library to send a series of specially crafted IP/TCP packets with malformed options to a target IP address. If the target is vulnerable and on the same local network, this can cause the device to crash and reboot. The README provides background on the vulnerability, affected versions, and mitigation steps, as well as usage instructions for the script. No hardcoded endpoints are present; the target IP is supplied by the user at runtime. The exploit is a POC and does not provide a customizable payload beyond the crafted packets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.