ZeroHour

CVE-2019-8662

CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.

Vendors
apple
Products
iphone os, mac os x, tvos, watchos
Weakness
CWE-416, CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news