First published: Mon May 13 2019(Updated: )
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
Credit: Ned Williamson Google Project ZeroNed Williamson Google Project ZeroNed Williamson Google Project ZeroNed Williamson Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.3 | |
Apple Mac OS X | <10.14.5 | |
Apple tvOS | <12.3 | |
Apple watchOS | <5.2.1 | |
Apple watchOS | <5.2.1 | 5.2.1 |
Apple iOS | <12.3 | 12.3 |
Apple tvOS | <12.3 | 12.3 |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8591 is a type confusion vulnerability that was fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1.
CVE-2019-8591 can allow an application to cause unexpected system termination or write kernel memory on affected Apple devices.
The severity of CVE-2019-8591 is high, with a CVSS score of 7.1.
To fix CVE-2019-8591, you need to update your Apple devices to the latest versions of iOS, macOS Mojave, tvOS, or watchOS, depending on the affected device.
You can find more information about CVE-2019-8591 on the Apple support website.