An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Quick Look" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://support.apple.com/HT208692 | vendor advisory |
http://www.securitytracker.com/id/1040604 | vdb entry third party advisory |
https://support.apple.com/HT208698 | vendor advisory |
https://support.apple.com/HT208696 | vendor advisory |
https://support.apple.com/HT208693 | vendor advisory |
http://www.securitytracker.com/id/1040608 | vdb entry third party advisory |