First published: Mon May 13 2019(Updated: )
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvOS 12.3, watchOS 5.2.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, iOS 13. Playing a malicious audio file may lead to arbitrary code execution.
Credit: riusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <13 | 13 |
Apple iPhone OS | <12.3 | |
Apple iPhone OS | >=12.3.1<13.0 | |
Apple Mac OS X | >=10.12.6<=10.14.5 | |
Apple Mac OS X | >=10.14.6<10.15 | |
Apple tvOS | <12.3 | |
Apple tvOS | >=12.4<13 | |
Apple watchOS | <5.2.1 | |
Apple tvOS | <13 | 13 |
Apple watchOS | <5.2.1 | 5.2.1 |
Apple macOS Catalina | <10.15 | 10.15 |
Apple iOS | <12.3 | 12.3 |
Apple tvOS | <12.3 | 12.3 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2019-8592.
The severity of CVE-2019-8592 is high.
The following software versions are affected by CVE-2019-8592: watchOS up to 5.2.1, macOS Catalina up to 10.15, iOS up to 13, iPhone OS up to 12.3, Mac OS X up to 10.14.5, tvOS up to 12.3.
To fix CVE-2019-8592, update to the following versions: watchOS 5.2.1 or later, macOS Catalina 10.15 or later, iOS 13 or later, iPhone OS 12.3.1 or later, Mac OS X 10.14.6 or later, tvOS 12.4 or later.
More information about CVE-2019-8592 can be found on the following links: [link1](https://support.apple.com/en-us/HT210722), [link2](https://support.apple.com/en-us/HT210634), [link3](https://support.apple.com/en-us/HT210119).