ZeroHour

CVE-2019-8526

KEVmass

Use-After-Free Local Privilege Escalation in Apple macOS

CISA: Apple macOS Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p51
Published
()
KEV added
AI analysis

CVE-2019-8526 is a use-after-free (CWE-416) memory-corruption flaw in Apple macOS that can be triggered by a low-privileged application already running on the target Mac, with no user interaction required. Successful exploitation lets an attacker gain elevated privileges beyond those of the triggering application, making it a local privilege escalation vector that is typically chained with other flaws. The issue is fixed in macOS Mojave 10.14.4, so users and organizations running earlier macOS builds are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-04-17, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. Related reporting on macOS watering-hole attacks delivering the DazzleSpy backdoor underscores active macOS targeting, but the provided data does not confirm a direct link to this specific CVE.

What to do: Upgrade affected Macs to macOS Mojave 10.14.4 or a later macOS release per Apple's instructions (CISA's required action), and inventory for any machines stuck on older builds using About This Mac or 'sw_vers -productVersion'. Because the flaw requires local execution, prioritize multi-user, shared, or high-risk Macs. Given confirmed in-the-wild exploitation, hunt for signs of post-exploitation on previously unpatched systems, keeping in mind macOS backdoor campaigns (e.g., DazzleSpy) reported against Mac users.

Affected
Apple macOS (Mac OS X)macOS versions prior to macOS Mojave 10.14.4 (fix shipped in macOS Mojave 10.14.4; CISA scope: Apple macOS)
Estimated exposure
massmacOS install base exceeds 100M active devices; likely millions of Macs were, or remain, on vulnerable pre-10.14.4 builds — Based on publicly estimated active Mac install base (well over 100 million devices) restricted to macOS Mojave builds before 10.14.4, a 2019 baseline that most current Macs have since upgraded past.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.

CISA Known Exploited Vulnerability
Affected
Apple macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
mac os x
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news