cbcvebase.
CVE-2019-8605
published 2019-12-18

CVE-2019-8605: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A…

PriorityP182high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
17.44%
96.8th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < iOS 12.3iOS 12.3
appleiphone_os< 12.312.3
applemac_os_x< 10.14.510.14.5
applemacos>= unspecified < macOS Mojave 10.14.5macOS Mojave 10.14.5
applemacos_mojave_10.14.6_supplemental_update
appletvos< 12.312.3
appletvos
appletvos>= unspecified < tvOS 12.3tvOS 12.3
applewatchos< 5.2.15.2.1
applewatchos
applewatchos>= unspecified < watchOS 5.2.1watchOS 5.2.1

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47409.zip
urlhttps://gist.github.com/ur0/a9b2d8088479a70665f729c4e9bf8720
filenamepayload.dylib
filenameircbin.plist
filenameirc_loader
path/androidmm/light
  • The CVE-2019-8605 (SockPuppet) exploit is reachable from the iOS app sandbox via TCP sockets using IPV6_3542PKTINFO (option 46) on AF_INET6/SOCK_STREAM sockets followed by disconnectx() and getsockopt() — monitor for this syscall sequence from sandboxed apps.
  • The Operation Poisoned News campaign delivered the CVE-2019-8605 kernel exploit via hidden iframes on watering-hole websites. Detect hidden iframe injection on news/forum pages targeting iOS Safari user-agents.
  • Kernel panic backtrace for CVE-2019-8605 crash shows _in6_selectsrc + 0x114 → _nd6_setdefaultiface + 0xd75 → _soconnectlock + 0x284. Use this call chain to identify crash dumps related to exploitation attempts.
  • lightSpy malware modules (ios_wechat, ios_qq, ios_telegram, KeyChain, FileManage, ShellCommandaaa, Locationaaa, WifiList, browser, Screenaaa, SoftInfoaaa) should be hunted as unexpected dylib files or processes on jailbroken iOS devices.
  • ·The original raw-socket PoC (exploit-db 46892) requires root privileges; however, the TCP-based reproducer is reachable from the iOS app sandbox, making it significantly more dangerous for real-world exploitation.
  • ·The Operation Poisoned News exploit chain targets iOS 12.1 and 12.2 specifically, using a silently patched Safari bug (no CVE) chained with CVE-2019-8605 for kernel privilege escalation. Devices on iOS 12.3+ (except 12.4) are not vulnerable to this specific chain.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.