CVE-2019-6205
HIGHiPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2 - Out-of-bounds Write
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6205. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a race condition in XNU's vm_map_copyin_internal function, leading to a TOCTOU issue where anonymous memory entries can be moved non-atomically, violating Mach message OOL memory semantics. The exploit demonstrates this by sending overlapping Mach messages to trigger the vulnerability.
Description
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
Exploits (1)
This PoC exploits a race condition in XNU's vm_map_copyin_internal function, leading to a TOCTOU issue where anonymous memory entries can be moved non-atomically, violating Mach message OOL memory semantics. The exploit demonstrates this by sending overlapping Mach messages to trigger the vulnerability.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H