CVE-2019-8506
KEVmassType Confusion in Apple WebKit (Safari, iOS, iCloud, iTunes) Allows Code Execution
CISA: Apple Multiple Products Type Confusion Vulnerability
CVE-2019-8506 is a type confusion flaw (CWE-843) in the web content processing engine shared by Apple's Safari browser and the iOS, tvOS, and watchOS operating systems, as well as iTunes and iCloud for Windows. It is triggered when a user processes maliciously crafted web content, such as by visiting an attacker-controlled webpage. Successful exploitation may allow the attacker to execute arbitrary code on the affected device or desktop. Anyone running Safari or iOS/tvOS versions before 12.2, watchOS before 5.2, or iTunes/iCloud for Windows before the fixed 12.9.4/7.11 releases is affected, and Red Hat Enterprise Linux (Desktop, Server, Workstation) is also listed among affected products in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-04, indicating known exploitation in the wild, though no public PoC is available and ransomware use is unknown.
What to do: Upgrade affected Apple software to the fixed releases: iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11, or later versions. Inventory Windows endpoints for iTunes and iCloud installations, which are frequently overlooked, and update or remove them. Red Hat Enterprise Linux users should apply Red Hat's updates addressing this CVE, and because this is a CISA KEV entry, patch per vendor instructions promptly.
| apple iPhone OS (iOS) | prior to 12.2 |
| apple tvOS | prior to 12.2 |
| apple watchOS | prior to 5.2 |
| apple Safari | prior to 12.1 |
| apple iTunes for Windows | prior to 12.9.4 |
| apple iCloud for Windows | prior to 7.11 |
| redhat Enterprise Linux Desktop / Server / Workstation | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown