First published: Mon Oct 28 2019(Updated: )
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6.1, tvOS 13.2, iOS 13.2 and iPadOS 13.2. An application may be able to execute arbitrary code with kernel privileges.
Credit: Jann Horn Google Project ZeroJann Horn Google Project ZeroJann Horn Google Project ZeroJann Horn Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <13.2 | |
Apple iPhone OS | <13.2 | |
Apple Mac OS X | <10.15.1 | |
Apple tvOS | <13.2 | |
Apple watchOS | <6.1 | |
Apple tvOS | <13.2 | 13.2 |
Apple iOS | <13.2 | 13.2 |
Apple iPadOS | <13.2 | 13.2 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Apple watchOS | <6.1 | 6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8829 is a memory corruption vulnerability in the Kernel that allows an application to execute arbitrary code with kernel privileges.
CVE-2019-8829 affects macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6.1, tvOS 13.2, iOS 13.2, and iPadOS 13.2.
To fix the CVE-2019-8829 vulnerability, update to the latest versions of macOS Catalina, Security Update, watchOS, tvOS, iOS, or iPadOS, depending on your affected software.
CVE-2019-8829 has a severity score of 7.8 (critical).
You can find more information about CVE-2019-8829 on the following references: [link1], [link2], [link3].