VulnerabilityModified
CVE-2019-8857
The issue was addressed with improved validation when an iCloud Link is created.
LOW 3.3EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/ipados · apple/iphone os
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.