First published: Mon May 13 2019(Updated: )
IOKit. A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Credit: Phoenhex qwerty @_niklasb @qwertyoruiopz @bkth_ Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.14.5 | |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2019-8606 is high.
CVE-2019-8606 allows a local user to load unsigned kernel extensions in macOS Mojave.
To fix CVE-2019-8606, update your macOS Mojave to version 10.14.5 or later.
CVE-2019-8606 affects macOS Mojave 10.14.5 and earlier.
The Common Weakness Enumeration ID of CVE-2019-8606 is CWE-362.