VulnerabilityAnalyzed
CVE-2019-8506
Apple Multiple Products Type Confusion Vulnerability
KEVHIGH 8.8EPSS 18.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 18.11% probability · 97th percentile
- CISA KEV
- Listed 4 May 2022 · due 25 May 2022
- Weakness
- CWE-843
- Affected
- apple/icloud · apple/itunes · apple/safari · apple/iphone os · apple/tvos · apple/watchos · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- product-security@apple.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-8506
References
- https://support.apple.com/HT209599Release Notes, Vendor Advisory
- https://support.apple.com/HT209601Release Notes, Vendor Advisory
- https://support.apple.com/HT209602Release Notes, Vendor Advisory
- https://support.apple.com/HT209603Release Notes, Vendor Advisory
- https://support.apple.com/HT209604Release Notes, Vendor Advisory
- https://support.apple.com/HT209605Release Notes, Vendor Advisory
- https://support.apple.com/HT209599Release Notes, Vendor Advisory
- https://support.apple.com/HT209601Release Notes, Vendor Advisory
- https://support.apple.com/HT209602Release Notes, Vendor Advisory
- https://support.apple.com/HT209603Release Notes, Vendor Advisory
- https://support.apple.com/HT209604Release Notes, Vendor Advisory
- https://support.apple.com/HT209605Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8506US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.