CVE-2019-8506
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products Type Confusion Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-843
מוצרים מושפעים
apple: icloud; apple: itunes; apple: safari; apple: iphone os; apple: tvos; apple: watchos; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation
קישורים
- https://support.apple.com/HT209599 Release NotesVendor Advisory
- https://support.apple.com/HT209601 Release NotesVendor Advisory
- https://support.apple.com/HT209602 Release NotesVendor Advisory
- https://support.apple.com/HT209603 Release NotesVendor Advisory
- https://support.apple.com/HT209604 Release NotesVendor Advisory
- https://support.apple.com/HT209605 Release NotesVendor Advisory
- https://support.apple.com/HT209599 Release NotesVendor Advisory
- https://support.apple.com/HT209601 Release NotesVendor Advisory
- https://support.apple.com/HT209602 Release NotesVendor Advisory
- https://support.apple.com/HT209603 Release NotesVendor Advisory