CVE-2019-8605
Apple iOS, Apple macOS, Apple tvOS
Published 18 Dec 2019 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 27 Jun 2022, with a remediation deadline of 18 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
References
- support.apple.com/HT210118 · Release Notes, Vendor Advisory
- support.apple.com/HT210119 · Release Notes, Vendor Advisory
- support.apple.com/HT210120 · Release Notes, Vendor Advisory
- support.apple.com/HT210122 · Release Notes, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605 · US Government Resource