← back
CVE-2019-8506

CVE-2019-8506

CVSS 8.8 HIGHEPSS 18.2%● KEVCWE-843
In short

A vulnerability in how Safari and Apple apps handle certain web content allows attackers to execute malicious code on your device. This happens when the software gets confused about what type of data it's processing, potentially giving attackers full control of your system.

Technical detail

A type confusion vulnerability in memory handling (CWE-843) allows remote code execution when processing maliciously crafted web content. The attack vector is network-based through web browsing; no user authentication or special privileges are required. Successful exploitation results in arbitrary code execution with the privileges of the affected application.

Summary generated and translated by AI from the official description.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →