CVE-2019-8546Sensitive Information Exposure in Apple Macos

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 24

Description

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5apple/macosunspecifiedmacOS Mojave 10.14.4
CVEListV5apple/watchosunspecifiedwatchOS 5.2
NVDapple/watchos< 5.2
NVDapple/mac_os_x< 10.14.4
CVEListV5apple/iosunspecifiediOS 12.2

🔴Vulnerability Details

2
GHSA
GHSA-83q2-qf2c-v85m: An access issue was addressed with additional sandbox restrictions2022-05-24
CVEList
CVE-2019-8546: An access issue was addressed with additional sandbox restrictions2019-12-18

📋Vendor Advisories

3
Apple
CVE-2019-8546: watchOS 5.22019-03-27
Apple
CVE-2019-8546: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra2019-03-25
Apple
CVE-2019-8546: iOS 12.22019-03-25
CVE-2019-8546 — Sensitive Information Exposure in Apple | cvebase