Memory Corruption Vulnerability in Apple iOS and macOS Products
CVE-2019-8688

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
18 December 2019

Summary

This vulnerability involves multiple memory corruption issues in various Apple products, which could be exploited through maliciously crafted web content. Successful exploitation may result in arbitrary code execution, potentially allowing attackers to gain control of affected devices. Apple addressed these issues with improved memory handling in numerous updates across their operating systems and applications.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Microsoft Store) < unspecified

iOS < unspecified

References

EPSS Score

23% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.