Memory Corruption in Apple Products Affects Multiple Platforms
CVE-2019-8685

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
18 December 2019

Summary

A series of identified memory corruption issues in Apple products could lead to arbitrary code execution when processing maliciously crafted web content. This vulnerability has been addressed with enhanced memory handling in several updates, ensuring improved security across different platforms including iOS, macOS, tvOS, watchOS, Safari, iTunes for Windows, and iCloud. Users should update to the latest versions to mitigate potential risks.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Microsoft Store) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.