First published: Mon Mar 25 2019(Updated: )
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. An application may be able to execute arbitrary code with kernel privileges.
Credit: Juwei Lin @panicaII Trend Micro Research working with Trend MicroJuwei Lin @panicaII Trend Micro Research working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.2 | |
Apple Mac OS X | <10.14.4 | |
Apple macOS Mojave | <10.14.4 | 10.14.4 |
Apple High Sierra | ||
Apple Sierra | ||
Apple iOS | <12.2 | 12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8529 is a memory corruption vulnerability in the IOKit SCSI component of Apple iOS and macOS Mojave.
CVE-2019-8529 has a severity of 7.8 (high).
Apple iOS versions up to but excluding 12.2, and macOS Mojave versions up to but excluding 10.14.4 are affected by CVE-2019-8529.
CVE-2019-8529 can be fixed by updating the affected software to iOS 12.2 or macOS Mojave 10.14.4.
You can find more information about CVE-2019-8529 on the Apple support page: [https://support.apple.com/en-us/HT209599](https://support.apple.com/en-us/HT209599).