Memory Corruption Vulnerability in Apple's iOS and macOS Products
CVE-2019-8666

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
18 December 2019

Summary

This vulnerability involves multiple memory corruption issues addressed in various Apple products through improved memory handling. When a user interacts with maliciously crafted web content, it may result in arbitrary code execution, potentially allowing attackers to exploit system functions and gain unauthorized control. The issue has been remediated in significant updates across several platforms.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Microsoft Store) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.