ZeroHour

CVE-2019-8605

KEVmass

Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution

CISA: Apple Multiple Products Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.

What to do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.

Affected
apple iphone os (iOS)versions prior to iOS 12.3 (fixed in iOS 12.3)
apple mac os x (macOS Mojave)versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5)
apple tvosversions prior to tvOS 12.3 (fixed in tvOS 12.3)
apple watchosversions prior to watchOS 5.2.1 (fixed in watchOS 5.2.1)
Estimated exposure
masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact… — Apple's active installed base exceeds a billion iOS/macOS devices worldwide, and any iPhone, Mac, Apple TV, or Apple Watch not updated past the fixed releases is potentially affected, though the flaw requires a local malicious application…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os, mac os x, tvos, watchos
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news