# CVE-2018-5383

## Summary

- **CVE ID:** CVE-2018-5383
- **Severity:** HIGH
- **CVSS Score:** 8 (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-325
- **Published:** Aug 7, 2018
- **Last Modified:** Mar 14, 2026

## Description

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

## Affected Products

- Apple — macOS (10.13 High Sierra)
- Apple — iOS (11)
- Android Open Source Project — Android (unspecified)

## References

- [CNA](http://www.cs.technion.ac.il/~biham/BT/)
- [CNA](http://www.securitytracker.com/id/1041432)
- [CNA](https://www.kb.cert.org/vuls/id/304725)
- [CNA](https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update)
- [CNA](http://www.securityfocus.com/bid/104879)
- [CNA](https://lists.debian.org/debian-lts-announce/2019/04/msg00005.html)
- [CNA](https://access.redhat.com/errata/RHSA-2019:2169)
- [CNA](https://usn.ubuntu.com/4094-1/)
- [CNA](https://usn.ubuntu.com/4095-2/)
- [CNA](https://usn.ubuntu.com/4095-1/)
- [CNA](https://usn.ubuntu.com/4118-1/)
- [CNA](https://usn.ubuntu.com/4351-1/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 68.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._