CVE-2019-8506
HIGH KEViCloud < 7.11 - Remote Code Execution via Type Confusion
Title source: llmExploitation Summary
CVE-2019-8506 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 4, 2022. EIP tracks 1 public exploit from researchers including Google Security Research.
AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in JavaScriptCore's inferred type mechanism to bypass watchpoints, allowing arbitrary memory corruption. It manipulates the regExpMatchesArrayWithGroupsStructure to achieve this by forcing the engine into a 'bad time' state.
Description
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
Exploits (1)
This exploit leverages a type confusion vulnerability in JavaScriptCore's inferred type mechanism to bypass watchpoints, allowing arbitrary memory corruption. It manipulates the regExpMatchesArrayWithGroupsStructure to achieve this by forcing the engine into a 'bad time' state.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H