⚠ Actively exploited
Added to CISA KEV on 2023-04-17. Federal agencies required to patch by 2023-05-08. Required action: Apply updates per vendor instructions..

CVE-2019-8526Use After Free in Apple Macos

CWE-416Use After Free7 documents6 sources
Severity
7.8HIGHNVD
EPSS
0.7%
top 29.03%
CISA KEV
KEV
Added 2023-04-17
Due 2023-05-08
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 18
KEV addedApr 17
KEV dueMay 8
CISA Required Action: Apply updates per vendor instructions.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-p8m9-gxw7-g5pf: A use after free issue was addressed with improved memory management2022-05-24
VulnCheck
Apple macOS Use-After-Free Vulnerability2019

📋Vendor Advisories

2
CISA
Apple macOS Use-After-Free Vulnerability2023-04-17
Apple
CVE-2019-8526: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra2019-03-25

🕵️Threat Intelligence

2
Sentinelone
10 macOS Malware Outbreaks from 20192019-07-01
Sentinelone
10 macOS Malware Outbreaks from 20192019-07-01