An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu" component. It allows attackers to execute arbitrary code in a privileged context because write and execute permissions are enabled during library loading.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "4.1.1"
}
],
"cpes": [
"cpe:2.3:a:apple:swift:*:*:*:*:*:ubuntu:*:*"
],
"vendor_product": "apple:swift"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-4220.json"
"2026-07-08T17:57:07Z"
[
{
"target": {
"file": "lib/Basic/Version.cpp",
"function": "getSwiftFullVersion"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2018-4220-c248d823",
"signature_version": "v1",
"source": "https://github.com/swiftlang/swift/commit/b61523a0207d6277c0e64a354f0d9187cf85e453",
"digest": {
"function_hash": "265955098139312753026840419377700005648",
"length": 214.0
}
},
{
"target": {
"file": "lib/Basic/Version.cpp"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2018-4220-d3834253",
"signature_version": "v1",
"source": "https://github.com/swiftlang/swift/commit/b61523a0207d6277c0e64a354f0d9187cf85e453",
"digest": {
"line_hashes": [
"1796450109439206812300957329771678800",
"276841013234405574054417792570126729615",
"124674513808532008237135124683863742925",
"150097780742484238016989027862275115710"
],
"threshold": 0.9
}
}
]