Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Exploitability: 1.8 | Impact: 3.6 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages9 packages ▶ CVEListV5 apple/macos unspecified — macOS Catalina 10.15.1 Show 4 more packages
🔴 Vulnerability Details2 GHSA GHSA-7jqm-x79h-jq97: A memory corruption issue was addressed with improved memory handling ↗ 2022-05-24 ▶ CVEList CVE-2019-8798: A memory corruption issue was addressed with improved memory handling ↗ 2019-12-18 ▶
📋 Vendor Advisories4 Apple CVE-2019-8798: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006 ↗ 2019-10-29 ▶ Apple CVE-2019-8798: watchOS 6.1 ↗ 2019-10-29 ▶ Apple CVE-2019-8798: tvOS 13.2 ↗ 2019-10-28 ▶ Apple CVE-2019-8798: iOS 13.2 and iPadOS 13.2 ↗ 2019-10-28 ▶
🕵️ Threat Intelligence2 Sentinelone Privilege Escalation | macOS Malware & The Path to Root Part 1 - SentinelLabs ↗ 2019-11-06 ▶ Sentinelone Privilege Escalation | macOS Malware & The Path to Root Part 1 ↗ 2019-11-06 ▶