CVE-2019-8518
HIGHiCloud < 7.11 - Memory Corruption via Malicious Web Content
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8518. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit targets a JIT optimization flaw in JavaScriptCore (CVE-2019-8518), where loop-invariant code motion incorrectly hoists an out-of-bounds array access before bounds checks, leading to a crash and potential arbitrary memory access.
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
Exploits (1)
This exploit targets a JIT optimization flaw in JavaScriptCore (CVE-2019-8518), where loop-invariant code motion incorrectly hoists an out-of-bounds array access before bounds checks, leading to a crash and potential arbitrary memory access.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H