VulnerabilityModified
CVE-2019-8846
A use after free issue was addressed with improved memory management.
HIGH 8.8EPSS 2.33%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- apple/icloud · apple/itunes · apple/safari · apple/ipados · apple/iphone os · apple/tvos · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210790Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210792Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210793Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210794Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210795Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210790Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210792Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210793Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210794Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210795Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.