CVE-2019-8526
KEVmassUse-After-Free Local Privilege Escalation in Apple macOS
CISA: Apple macOS Use-After-Free Vulnerability
CVE-2019-8526 is a use-after-free (CWE-416) memory-corruption flaw in Apple macOS that can be triggered by a low-privileged application already running on the target Mac, with no user interaction required. Successful exploitation lets an attacker gain elevated privileges beyond those of the triggering application, making it a local privilege escalation vector that is typically chained with other flaws. The issue is fixed in macOS Mojave 10.14.4, so users and organizations running earlier macOS builds are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-04-17, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. Related reporting on macOS watering-hole attacks delivering the DazzleSpy backdoor underscores active macOS targeting, but the provided data does not confirm a direct link to this specific CVE.
What to do: Upgrade affected Macs to macOS Mojave 10.14.4 or a later macOS release per Apple's instructions (CISA's required action), and inventory for any machines stuck on older builds using About This Mac or 'sw_vers -productVersion'. Because the flaw requires local execution, prioritize multi-user, shared, or high-risk Macs. Given confirmed in-the-wild exploitation, hunt for signs of post-exploitation on previously unpatched systems, keeping in mind macOS backdoor campaigns (e.g., DazzleSpy) reported against Mac users.
| Apple macOS (Mac OS X) | macOS versions prior to macOS Mojave 10.14.4 (fix shipped in macOS Mojave 10.14.4; CISA scope: Apple macOS) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
- Affected
- Apple macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- mac os x
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H