CVE-2019-8702Resource Exposure in Apple Macos

CWE-668Resource Exposure6 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateDec 24

Description

This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDapple/tvos< 12.4
CVEListV5apple/macosunspecified10.14+1
NVDapple/mac_os_x10.1210.12.6+4
CVEListV5apple/iosunspecified12.4
NVDapple/iphone_os< 12.4

🔴Vulnerability Details

2
GHSA
GHSA-hhv4-6pch-f75f: This issue was addressed with a new entitlement2021-12-24
CVEList
CVE-2019-8702: This issue was addressed with a new entitlement2021-12-23

📋Vendor Advisories

3
Apple
CVE-2019-8702: iOS 12.42019-07-22
Apple
CVE-2019-8702: tvOS 12.42019-07-22
Apple
CVE-2019-8702: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra2019-07-22
CVE-2019-8702 — Resource Exposure in Apple Macos | cvebase