Junglewise Threat Intelligence

CVE-2019-8605: Apple Multiple Products Use-After-Free Vulnerability

CVE-2019-8605 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-27

Technologies: Apple Tvos, Apple watchOS, Apple Multiple Products. Vendors: Apple.

Executive brief

A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS allows a malicious application to execute arbitrary code with system privileges due to improper memory management. The issue was addressed by improving memory management in various Apple operating system updates.

Affected products

  • Apple iOS before 12.3
  • Apple macOS Mojave before 10.14.5
  • Apple tvOS before 12.3
  • Apple watchOS before 5.2.1

Timeline

  • 2019-12-18: disclosed: NVD Published Date
  • 2022-06-27: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-27: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats