cbcvebase.
CVE-2019-8605
published 2019-12-18

CVE-2019-8605: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < iOS 12.3iOS 12.3
appleiphone_os< 12.312.3
applemac_os_x< 10.14.510.14.5
applemacos>= unspecified < macOS Mojave 10.14.5macOS Mojave 10.14.5
applemacos_mojave_10.14.6_supplemental_update
appletvos< 12.312.3
appletvos
appletvos>= unspecified < tvOS 12.3tvOS 12.3
applewatchos< 5.2.15.2.1
applewatchos
applewatchos>= unspecified < watchOS 5.2.1watchOS 5.2.1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH