First published: Mon Oct 07 2019(Updated: )
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. An attacker in a privileged network position may be able to leak sensitive user information.
Credit: product-security@apple.com Pawel Gocyla ING Tech PolandPawel Gocyla ING Tech Poland
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.15 | |
Apple macOS Catalina | <10.15 | 10.15 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2019-8736.
The severity is medium with a CVSS score of 6.5.
The affected software versions are macOS Catalina up to and including 10.15, and macOS Catalina 10.15.1 (up to but not including).
An attacker in a privileged network position may be able to leak sensitive user information.
Yes, Apple has fixed this issue in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006.