CVE-2018-4091

CRITICAL

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism.

Affects 1 product across 1 vendor.

BCS7.66
CVSS 3.010.0
EPSS1.8%
Percentile76th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2018. A critical vulnerability affects Apple systems (CVE-2018-4091). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2018-GLOBAL-129998-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-4091?
This vulnerability was disclosed in 2018. A critical vulnerability affects Apple systems (CVE-2018-4091). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2018-4091?
CVE-2018-4091 has CVSS 10.0 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 1.8%.
Is CVE-2018-4091 actively exploited?
No confirmed active exploitation of CVE-2018-4091 as of 2026-05-30.
How do I remediate CVE-2018-4091?
Priority: MEDIUM. Advisory: https://support.apple.com/HT208465 PSIRT: [email protected]
What systems are affected by CVE-2018-4091?
CVE-2018-4091 affects: Apple.
Vulnerability Details
CVE IDCVE-2018-4091
BSIDBS-2018-GLOBAL-129998-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2018-04-03
Last Modified2024-11-21
ICS Relevance0%
SourceNVD
Official Description

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Apple Mac Os X
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 3044 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash6ec082c8926deeb9d4a08f474fe9ff04631e83e8bf3f987adf3bf8212d3ca34743c7fcbd39994bd6edd3dff826777c04e3bac68b2146a2c310938bb5358c0a0c
Related CVEs affecting Apple
CVE-2007-2387 10.0 Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardwa... CVE-2014-0590 10.0 Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on W... CVE-2014-4488 10.0 IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple T... CVE-2003-0426 10.0 The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f s... CVE-2003-0502 10.0 Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attacke...
View all Apple CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →