CVE-2019-6214
HIGHiPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2, watchOS < 5.1.3 - Sandbox Escape via Type Confusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6214. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a type confusion and memory safety issue in the `com.apple.iohideventsystem` service on macOS and iOS. It triggers a use-after-free (UaF) by calling `io_hideventsystem_unregister_record_service_changed_notification` multiple times, leading to arbitrary reference drops on an `IOHIDEventSystem` object.
Description
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
Exploits (1)
This exploit demonstrates a type confusion and memory safety issue in the `com.apple.iohideventsystem` service on macOS and iOS. It triggers a use-after-free (UaF) by calling `io_hideventsystem_unregister_record_service_changed_notification` multiple times, leading to arbitrary reference drops on an `IOHIDEventSystem` object.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H