ZeroHour

CVE-2019-8506

KEVmass

Type Confusion in Apple WebKit (Safari, iOS, iCloud, iTunes) Allows Code Execution

CISA: Apple Multiple Products Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2019-8506 is a type confusion flaw (CWE-843) in the web content processing engine shared by Apple's Safari browser and the iOS, tvOS, and watchOS operating systems, as well as iTunes and iCloud for Windows. It is triggered when a user processes maliciously crafted web content, such as by visiting an attacker-controlled webpage. Successful exploitation may allow the attacker to execute arbitrary code on the affected device or desktop. Anyone running Safari or iOS/tvOS versions before 12.2, watchOS before 5.2, or iTunes/iCloud for Windows before the fixed 12.9.4/7.11 releases is affected, and Red Hat Enterprise Linux (Desktop, Server, Workstation) is also listed among affected products in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-04, indicating known exploitation in the wild, though no public PoC is available and ransomware use is unknown.

What to do: Upgrade affected Apple software to the fixed releases: iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11, or later versions. Inventory Windows endpoints for iTunes and iCloud installations, which are frequently overlooked, and update or remove them. Red Hat Enterprise Linux users should apply Red Hat's updates addressing this CVE, and because this is a CISA KEV entry, patch per vendor instructions promptly.

Affected
apple iPhone OS (iOS)prior to 12.2
apple tvOSprior to 12.2
apple watchOSprior to 5.2
apple Safariprior to 12.1
apple iTunes for Windowsprior to 12.9.4
apple iCloud for Windowsprior to 7.11
redhat Enterprise Linux Desktop / Server / Workstation
Estimated exposure
mass≈1 billion+ users/devices — Apple's active iPhone/iPad installed base runs to hundreds of millions or more, Safari has historically had on the order of a billion users, and iTunes/iCloud for Windows shipped on tens of millions of Windows PCs, so the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
appleredhat
Products
icloud, itunes, safari, iphone os, tvos, watchos, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news