CVE-2019-8605
KEVmassUse-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution
CISA: Apple Multiple Products Use-After-Free Vulnerability
CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.
What to do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.
| apple iphone os (iOS) | versions prior to iOS 12.3 (fixed in iOS 12.3) |
| apple mac os x (macOS Mojave) | versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5) |
| apple tvos | versions prior to tvOS 12.3 (fixed in tvOS 12.3) |
| apple watchos | versions prior to watchOS 5.2.1 (fixed in watchOS 5.2.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os, mac os x, tvos, watchos
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H