First published: Mon May 13 2019(Updated: )
Kernel. A use after free issue was addressed with improved memory management.
Credit: Ned Williamson Google Project Zero product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <5.2.1 | 5.2.1 |
Apple iPhone OS | <12.3 | |
Apple Mac OS X | <10.14.5 | |
Apple tvOS | <12.3 | |
Apple watchOS | <5.2.1 | |
Apple Multiple Products | ||
<12.3 | ||
<10.14.5 | ||
<12.3 | ||
<5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8605 is a use-after-free vulnerability in Apple Multiple Products that allows a malicious application to execute arbitrary code with system privileges.
Multiple Apple products are affected by CVE-2019-8605, including iOS, macOS, tvOS, and watchOS.
CVE-2019-8605 has a severity rating of critical.
To fix CVE-2019-8605, update your iOS device to version 12.3 or later, update macOS to version 10.14.5 or later, update tvOS to version 12.3 or later, and update watchOS to version 5.2.1 or later.
You can find more information about CVE-2019-8605 on the Apple support website. (Reference: https://support.apple.com/HT210118, https://support.apple.com/HT210119, https://support.apple.com/HT210120)