First published: Thu Sep 19 2019(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Credit: natashenka Samuel Groß Google Project ZeroSamuel Groß natashenka Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zeronatashenka Samuel Groß Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.10.1 | 12.10.1 |
Apple iCloud for Windows | <7.14 | 7.14 |
Apple iCloud for Windows | <10.7 | 10.7 |
Apple macOS Catalina | <10.15 | 10.15 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Apple watchOS | <6 | 6 |
Apple tvOS | <13 | 13 |
Apple iOS | <13 | 13 |
Apple Icloud Windows | <7.14 | |
Apple Icloud Windows | >=10.0<10.7 | |
Apple Itunes Windows | <12.10.1 | |
Apple iPhone OS | <13.1 | |
Apple Mac OS X | <10.15 | |
Apple tvOS | <13 | |
Apple watchOS | <6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-8746 is a vulnerability in Foundation that allows for an out-of-bounds read due to improved input validation.
CVE-2019-8746 has a severity rating of 9.8 (Critical).
CVE-2019-8746 affects macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, Security Update 2019-006, watchOS 6, and iTunes 12.10.1 for Windows.
To fix CVE-2019-8746, update your software to macOS Catalina 10.15.1, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, Security Update 2019-006, watchOS 6, or iTunes 12.10.1 for Windows.
You can find more information about CVE-2019-8746 on the Apple support website: [link](https://support.apple.com/en-us/HT210722).