CVE-2019-8613
published 2019-12-18CVE-2019-8613: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
13.29%
96.0th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < iOS 12.3 | iOS 12.3 |
| apple | iphone_os | < 12.3 | 12.3 |
| apple | tvos | < 12.3 | 12.3 |
| apple | tvos | >= unspecified < tvOS 12.3 | tvOS 12.3 |
| apple | watchos | < 5.2.1 | 5.2.1 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < watchOS 5.2.1 | watchOS 5.2.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unsolicited inbound SMS messages with VVM-specific PID fields that contain IMAP server URLs — these are the attacker's initial delivery vector to redirect the device to a malicious IMAP server. ↗
- →Detect IMAP NAMESPACE command responses that are malformed or followed immediately by a LOGOUT command — this is the server-side trigger for the use-after-free in [MFIMAPConnection _doNamespaceCommand]. ↗
- →Alert on iOS/tvOS/watchOS devices initiating IMAP connections (ports 993 or 143) to servers not associated with the device's configured carrier VVM infrastructure, especially following receipt of an SMS. ↗
- →Look for crashes or unexpected termination of the Mail Message Framework process on Apple devices, particularly involving selector calls on freed objects after a NAMESPACE command failure. ↗
- ·Exploitability is carrier-dependent: the attack requires the carrier network to permit VVM IMAP connections to external servers. T-Mobile was observed to block such connections, while AT&T did not. ↗
- ·The VVM SMS PID value used to trigger the attack varies by carrier, meaning attacker SMS payloads must be tailored per target carrier. ↗
- ·A potential bypass for carrier-level blocking may exist by hosting the malicious IMAP server on a peer device within the same mobile network, though this was not confirmed by the researcher. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8613: watchOS 5.2.1
vendor_apple·2019-05-13·CVSS 9.8
CVE-2019-8613 [CRITICAL] CVE-2019-8613: watchOS 5.2.1
Apple Security Update: About the security content of watchOS 5.2.1
Product: watchOS
Version: 5.2.1
CVE: CVE-2019-8613
Component: Mail Message Framework
Impact: A remote attacker may be able to cause arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2019-8613: iOS 12.3
vendor_apple·2019-05-13·CVSS 9.8
CVE-2019-8613 [CRITICAL] CVE-2019-8613: iOS 12.3
Apple Security Update: About the security content of iOS 12.3
Product: iOS
Version: 12.3
CVE: CVE-2019-8613
Component: Mail Message Framework
Impact: A remote attacker may be able to cause arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
GHSA
GHSA-xx2p-7x2v-j239: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2022-05-24
CVE-2019-8613 [HIGH] GHSA-xx2p-7x2v-j239: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.
Project0
The Fully Remote Attack Surface of the iPhone - Project Zero
project_zero·2019-08-01
CVE-2019-8613 The Fully Remote Attack Surface of the iPhone - Project Zero
Posted by Natalie Silvanovich, Project Zero
While there have been several rumours and reports of fully remote vulnerabilities affecting the iPhone being used by attackers in the last couple of years, limited information is available about the technical details of these vulnerabilities, as well as the underlying attack surface they occur in. I investigated the remote, interaction-less attack surface of the iPhone, and found several serious vulnerabilities.
Vulnerabilities are considered ‘remote’ when the attacker does not require any physical or network proximity to the target to be able to use the vulnerability. Remote vulnerabilities are described as ‘fully remote’, ‘interaction-less’ or ‘zero click’ when they do not require any physical interaction from the target to be exploited, an
No detection rules found.
No writeups or analysis indexed.
2019-12-18
Published