First published: Mon May 13 2019(Updated: )
MobileInstallation. A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Credit: Dany Lisiansky @DanyL931 Dany Lisiansky @DanyL931 Dany Lisiansky @DanyL931 Dany Lisiansky @DanyL931 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.3 | |
Apple Mac OS X | <10.14.5 | |
Apple tvOS | <12.3 | |
Apple watchOS | <5.2.1 | |
Apple watchOS | <5.2.1 | 5.2.1 |
Apple iOS | <12.3 | 12.3 |
Apple tvOS | <12.3 | 12.3 |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8568 is a vulnerability that exists in the handling of symlinks in Apple's iOS, macOS Mojave, tvOS, and watchOS.
The details of exploiting CVE-2019-8568 are not provided, but it is described as a local user being able to modify protected parts of the file system.
The severity of CVE-2019-8568 is medium with a CVSS score of 5.5.
The vulnerability affects macOS Mojave 10.14.5, iOS 12.3, tvOS 12.3, and watchOS 5.2.1.
CVE-2019-8568 was addressed with improved validation of symlinks in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1.