First published: Tue Dec 10 2019(Updated: )
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
Credit: Cim Stordal CogniteDr Silvio Cesare InfoSectCim Stordal CogniteDr Silvio Cesare InfoSectApple pattern-f @pattern_F_ WaCaiCim Stordal CogniteDr Silvio Cesare InfoSectCim Stordal CogniteDr Silvio Cesare InfoSect product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <13.3 | 13.3 |
Apple iPadOS | <13.3 | |
Apple iPhone OS | <13.3 | |
Apple Mac OS X | <10.15.2 | |
Apple tvOS | <13.3 | |
Apple watchOS | <6.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8838 is a vulnerability in the Kernel that allows for memory corruption, which has been addressed with improved memory handling.
The affected software includes macOS Catalina version 10.15.2, Apple Mojave, and Apple High Sierra.
To fix CVE-2019-8838, make sure to update your macOS Catalina to version 10.15.2 or apply any relevant patches or updates provided by Apple for Mojave and High Sierra.
You can find more information about CVE-2019-8838 on Apple's support website at the following link: https://support.apple.com/en-us/HT210788
The severity of CVE-2019-8838 is not specified.