CVE-2019-8780Apple IOS AND Ipados vulnerability

4 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 67.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13. A malicious application may be able to determine kernel memory layout.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5apple/tvosunspecified13
NVDapple/tvos< 13.0
CVEListV5apple/ios_and_ipadosunspecified13.1
Appleapple/tvos13

🔴Vulnerability Details

1
GHSA
GHSA-phvp-p2gr-2f3f: The issue was addressed with improved permissions logic2022-05-24

📋Vendor Advisories

2
Apple
CVE-2019-8780: tvOS 132019-09-24
Apple
CVE-2019-8780: iOS 13.1 and iPadOS 13.12019-09-24
CVE-2019-8780 — Apple IOS AND Ipados vulnerability | cvebase