CVE-2019-8602
published 2019-12-18CVE-2019-8602: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1…
PriorityP345high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
10.26%
95.2th percentile
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.12 | 7.12 |
| apple | icloud | >= 10.0 < 10.4 | 10.4 |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.12 | iCloud for Windows 7.12 |
| apple | ios | — | — |
| apple | ios | >= unspecified < iOS 12.3 | iOS 12.3 |
| apple | iphone_os | < 12.3 | 12.3 |
| apple | itunes | < 12.9.5 | 12.9.5 |
| apple | itunes_for_windows | — | — |
| apple | itunes_for_windows | >= unspecified < iTunes for Windows 12.9.5 | iTunes for Windows 12.9.5 |
| apple | mac_os_x | < 10.14.5 | 10.14.5 |
| apple | macos | >= unspecified < macOS Mojave 10.14.5 | macOS Mojave 10.14.5 |
| apple | macos_mojave_10.14.5_security_update_2019-003_high_sierra_security_update_2019-0 | — | — |
| apple | safari | < 12.1.1 | 12.1.1 |
| apple | tvos | < 12.3 | 12.3 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < tvOS 12.3 | tvOS 12.3 |
| apple | watchos | < 5.2.1 | 5.2.1 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < watchOS 5.2.1 | watchOS 5.2.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8602: iCloud for Windows 10.4
vendor_apple·2019-06-11·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: iCloud for Windows 10.4
Apple Security Update: About the security content of iCloud for Windows 10.4
Product: iCloud for Windows
Version: 10.4
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: iTunes for Windows 12.9.5
vendor_apple·2019-05-28·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: iTunes for Windows 12.9.5
Apple Security Update: About the security content of iTunes for Windows 12.9.5
Product: iTunes for Windows
Version: 12.9.5
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: iCloud for Windows 7.12
vendor_apple·2019-05-28·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: iCloud for Windows 7.12
Apple Security Update: About the security content of iCloud for Windows 7.12
Product: iCloud for Windows
Version: 7.12
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Product: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: watchOS 5.2.1
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: watchOS 5.2.1
Apple Security Update: About the security content of watchOS 5.2.1
Product: watchOS
Version: 5.2.1
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: tvOS 12.3
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: tvOS 12.3
Apple Security Update: About the security content of tvOS 12.3
Product: tvOS
Version: 12.3
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2019-8602: iOS 12.3
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8602 [HIGH] CVE-2019-8602: iOS 12.3
Apple Security Update: About the security content of iOS 12.3
Product: iOS
Version: 12.3
CVE: CVE-2019-8602
Component: SQLite
Impact: A malicious application may be able to elevate privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
GHSA
GHSA-cmhq-qhr2-gp3j: A memory corruption issue was addressed by removing the vulnerable code
ghsa_unreviewed·2022-05-24
CVE-2019-8602 [MEDIUM] GHSA-cmhq-qhr2-gp3j: A memory corruption issue was addressed by removing the vulnerable code
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
No detection rules found.
No public exploits indexed.
Checkpoint
12th August – Threat Intelligence Bulletin
blogs_checkpoint·2019-08-12
CVE-2019-8602 12th August – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 12th August – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 12th August 2019, please download our Threat Intelligence Bulletin .
Top attacks and breaches
AT&T employees have been bribed to unlock more than 2 million mobile devices and plant malware on the company’s internal network. The malware allowed the threat actor to gather the telco’s confidential and proprietary data and to remotely process unauthorized unlock requests.
GermanWiper , suspected to be a variant
Checkpoint
SELECT code_execution FROM * USING SQLite;
blogs_checkpoint·2019-08-10
CVE-2019-8457 SELECT code_execution FROM * USING SQLite;
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## SELECT code_execution FROM * USING SQLite;
## Gaining code execution using a malicious SQLite database
Research By: Omer Gull
## tl;dr
SQLite is one of the most deployed software in
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://support.apple.com/HT210124https://support.apple.com/HT210125https://support.apple.com/HT210212https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://support.apple.com/HT210124https://support.apple.com/HT210125https://support.apple.com/HT210212
2019-12-18
Published