First published: Mon Mar 25 2019(Updated: )
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
Credit: Luke Deshotels North Carolina State UniversityJordan Beichler North Carolina State UniversityWilliam Enck North Carolina State UniversityCostin Carabaș University POLITEHNICA of Bucharest Răzvan Deaconescu University POLITEHNICA of Bucharest product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <12.2 | 12.2 |
macOS Mojave | <10.14.4 | 10.14.4 |
macOS High Sierra | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <12.2 | 12.2 |
Apple iOS, iPadOS, and watchOS | <5.2 | 5.2 |
iOS | <12.2 | |
Apple iOS and macOS | <10.14.4 | |
tvOS | <12.2 | |
Apple iOS, iPadOS, and watchOS | <5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8502 is a vulnerability that existed in the handling of dictation requests in Siri.
CVE-2019-8502 affected multiple Apple devices, including macOS Mojave, High Sierra, Sierra, iOS, tvOS, and watchOS.
CVE-2019-8502 has a severity level of medium, with a CVSS score of 3.3.
CVE-2019-8502 was fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, and watchOS 5.2 with improved validation.
Yes, a malicious application could exploit CVE-2019-8502 to initiate a Dictation request without user authorization.