CVE-2019-8605
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
- Affected products
- Ios, Macos Mojave, Tvos, Watchos
- Apple Iphone Os
- < 12.3
- Apple Mac Os X
- < 10.14.5
- Apple Tvos
- < 12.3
- Apple Watchos
- < 5.2.1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 17.5% (97th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2019-12-18
CVE-2019-8605 at NVD
7 known exploits for CVE-2019-8605
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-8605
Exploit for Type Confusion in Apple Iphone_Os
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
macOS < 10.14.5 / iOS < 12.3 XNU - in6_pcbdetach Stale Pointer Use-After-Free Exploit
Apple macOS 10.14.5 iOS 12.3 XNU - in6_pcbdetach Stale Pointer Use-After-Free
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
XNU Stale Pointer Use-After-Free