CVE-2019-8506
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
- Apple Icloud
- < 7.11
- Apple Itunes
- < 12.9.4
- Apple Safari
- < 12.1
- Apple Iphone Os
- < 12.2
- Apple Tvos
- < 12.2
- Apple Watchos
- < 5.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 18.1% (97th percentile)
- Weakness
- CWE-843
- NVD status
- Analyzed
- Published
- 2019-12-18
CVE-2019-8506 at NVD
2 known exploits for CVE-2019-8506
Proof-of-concept code and exploit modules indexed by Sploitus