Multiple Memory Corruption Issues in iOS, iCloud, Safari, tvOS, watchOS, and iTunes by Apple
CVE-2019-8734

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 October 2020

Summary

This vulnerability stems from multiple memory corruption issues identified in various Apple products, allowing attackers to exploit improved memory handling protocols. Maliciously crafted web content can lead to arbitrary code execution, presenting significant risks for users operating affected versions of iOS, Safari, iCloud, and other platforms. Preventive measures include updating to fixed versions to mitigate potential threats.

Affected Version(s)

iCloud for Windows < 10.7

iCloud for Windows < 7.14

iOS < 13

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.