CVE-2019-8554
published 2019-12-18CVE-2019-8554: A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.12%
62.8th percentile
A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < iOS 12.2 | iOS 12.2 |
| apple | iphone_os | < 12.2 | 12.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9x9m-g8ph-2mv8: A permissions issue existed in the handling of motion and orientation data
ghsa_unreviewed·2022-05-24
CVE-2019-8554 [MEDIUM] GHSA-9x9m-g8ph-2mv8: A permissions issue existed in the handling of motion and orientation data
A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
Apple
CVE-2019-8554: iOS 12.2
vendor_apple·2019-03-25·CVSS 6.5
CVE-2019-8554 [MEDIUM] CVE-2019-8554: iOS 12.2
Apple Security Update: About the security content of iOS 12.2
Product: iOS
Version: 12.2
CVE: CVE-2019-8554
Component: Safari
Impact: A website may be able to access sensor information without user consent
Description: A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published