First published: Mon Oct 28 2019(Updated: )
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
Credit: Cheolung Lee LINECheolung Lee LINEfound by OSS-Fuzz Soyeon Park SSLab at Georgia TechJunDong Xie AntCheolung Lee LINESoyeon Park SSLab at Georgia TechCheolung Lee LINESamuel Groß Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroCheolung Lee LINECheolung Lee LINEfound by OSS-Fuzz Soyeon Park SSLab at Georgia TechJunDong Xie AntCheolung Lee LINESoyeon Park SSLab at Georgia TechCheolung Lee LINESamuel Groß Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project Zerozhunki Codesafe Team of Legendsec at QiSamuel Groß Google Project Zerofound by OSS-Fuzz found by OSS-Fuzz Soyeon Park SSLab at Georgia TechJunDong Xie AntSoyeon Park SSLab at Georgia TechSamuel Groß Google Project ZeroCheolung Lee LINECheolung Lee LINEfound by OSS-Fuzz Soyeon Park SSLab at Georgia TechJunDong Xie AntCheolung Lee LINESoyeon Park SSLab at Georgia TechCheolung Lee LINESamuel Groß Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroCheolung Lee LINECheolung Lee LINEfound by OSS-Fuzz Soyeon Park SSLab at Georgia TechJunDong Xie AntCheolung Lee LINESoyeon Park SSLab at Georgia TechCheolung Lee LINESamuel Groß Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project ZeroSergei Glazunov Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.10.2 | 12.10.2 |
Apple Safari | <13.0.3 | 13.0.3 |
Apple watchOS | <6.1 | 6.1 |
Apple tvOS | <13.2 | 13.2 |
redhat/webkitgtk | <2.26.0 | 2.26.0 |
Apple iOS | <13.2 | 13.2 |
Apple iPadOS | <13.2 | 13.2 |
Apple Itunes Windows | <12.10.2 | |
Apple Safari | <13.0.3 | |
Apple iPadOS | <13.2 | |
Apple iPhone OS | <13.2 | |
Apple tvOS | <13.2 | |
Apple watchOS | <6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8808 is a vulnerability in WebKit that allows for arbitrary code execution when processing malicious web content.
CVE-2019-8808 has a severity rating of 8.8, which is considered high.
CVE-2019-8808 affects iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, and iTunes for Windows 12.10.2.
To fix CVE-2019-8808, you should update your software to the fixed versions: iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, and iTunes for Windows 12.10.2.
You can find more information about CVE-2019-8808 on the Apple support website (https://support.apple.com/en-us/HT210721, https://support.apple.com/en-us/HT210726) and the Red Hat security advisory (https://access.redhat.com/security/cve/CVE-2019-8808).