First published: Mon May 13 2019(Updated: )
Archive Utility. A logic issue was addressed with improved validation.
Credit: Ash Fox Fitbit Product Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.14.5 | |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2019-8640.
The severity of CVE-2019-8640 is high with a CVSS score of 7.5.
The affected software includes macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, and Security Update 2019-003 Sierra.
The vulnerability can be fixed by updating to macOS Mojave 10.14.5, or applying Security Update 2019-003 for High Sierra or Sierra.
CVE-2019-8640 is a logic issue in Archive Utility that was addressed with improved validation. A sandboxed process may be able to circumvent sandbox restrictions.