CVE-2019-8746Out-of-bounds Read in Apple Macos

CWE-125Out-of-bounds Read11 documents4 sources
Severity
9.8CRITICALNVD
EPSS
2.3%
top 15.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages10 packages

CVEListV5apple/macosunspecified10.15+3
NVDapple/icloud10.010.7+1
NVDapple/mac_os_x< 10.15
CVEListV5apple/tvosunspecified13
NVDapple/tvos< 13

🔴Vulnerability Details

2
GHSA
GHSA-wc35-x492-36g5: An out-of-bounds read was addressed with improved input validation2022-05-24
CVEList
CVE-2019-8746: An out-of-bounds read was addressed with improved input validation2020-10-27

📋Vendor Advisories

8
Apple
CVE-2019-8746: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-0062019-10-29
Apple
CVE-2019-8746: macOS Catalina 10.152019-10-07
Apple
CVE-2019-8746: iCloud for Windows 10.72019-10-07
Apple
CVE-2019-8746: iTunes 12.10.1 for Windows2019-10-07
Apple
CVE-2019-8746: iCloud for Windows 7.142019-10-07
CVE-2019-8746 — Out-of-bounds Read in Apple Macos | cvebase