First published: Mon Mar 25 2019(Updated: )
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
Credit: Weibo Wang @ma1fan Qihoo 360 Nirvan TeamStefan Esser Antid0te UGWeibo Wang @ma1fan Qihoo 360 Nirvan TeamStefan Esser Antid0te UGWeibo Wang @ma1fan Qihoo 360 Nirvan TeamStefan Esser Antid0te UGWeibo Wang @ma1fan Qihoo 360 Nirvan TeamStefan Esser Antid0te UG product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <12.2 | 12.2 |
Apple iOS | <12.2 | 12.2 |
Apple macOS | <10.14.4 | 10.14.4 |
Apple High Sierra | ||
Apple Sierra | ||
Apple iPhone OS | <12.2 | |
macOS Yosemite | <10.14.4 | |
Apple tvOS | <12.2 | |
Apple watchOS | <5.2 | |
watchOS | <5.2 | 5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2019-6207.
The severity of CVE-2019-6207 is medium, with a severity value of 5.5.
This vulnerability can be fixed by updating to the latest versions of the affected software: iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, and watchOS 5.2.
The impact of this vulnerability is the disclosure of kernel memory, which could be used by a malicious application to determine kernel memory layout.
You can find more information about this vulnerability on the Apple support page: [link](https://support.apple.com/en-us/HT209599).