First published: Mon Mar 25 2019(Updated: )
WebKit. A use after free issue was addressed with improved memory management.
Credit: dwfault working at ADLab VenustechApple dwfault working at ADLab VenustechApple dwfault working at ADLab VenustechApple dwfault working at ADLab VenustechApple dwfault working at ADLab VenustechApple product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <12.1 | 12.1 |
Apple iCloud for Windows | <7.11 | 7.11 |
Apple iTunes for Windows | <12.9.4 | 12.9.4 |
Apple tvOS | <12.2 | 12.2 |
Apple iOS | <12.2 | 12.2 |
Apple Icloud Windows | <7.11 | |
Apple Itunes Windows | <12.9.4 | |
Apple Safari | <12.1 | |
Apple iPhone OS | <12.2 | |
Apple tvOS | <12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-7285 is a use after free vulnerability in WebKit that allows arbitrary code execution.
Versions up to iOS 12.2 are affected by CVE-2019-7285.
Versions up to tvOS 12.2 are affected by CVE-2019-7285.
Versions up to Safari 12.1 are affected by CVE-2019-7285.
To fix CVE-2019-7285, update your affected software to iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, or iCloud for Windows 7.11.