First published: Mon Oct 07 2019(Updated: )
An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.
Credit: product-security@apple.com Jens Müller Ruhr University BochumFabian Ising FH MVladislav Mladenov Ruhr University BochumChristian Mainka Ruhr University BochumSebastian Schinzel FH M Jörg Schwenk Ruhr University BochumJens Müller Ruhr University BochumFabian Ising FH MVladislav Mladenov Ruhr University BochumChristian Mainka Ruhr University BochumSebastian Schinzel FH M Jörg Schwenk Ruhr University Bochum
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.15 | |
Apple macOS Catalina | <10.15 | 10.15 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8772 is a vulnerability in PDFKit that allows an attacker to exfiltrate the contents of an encrypted PDF.
CVE-2019-8772 affects macOS Catalina versions up to 10.15.1.
CVE-2019-8772 has a severity rating of 7.5, which is considered high.
To fix CVE-2019-8772, update macOS Catalina to version 10.15.1 or later.
You can find more information about CVE-2019-8772 on the Apple Support website.