CVE-2019-8565

HIGH

Mac OS X Feedback Assistant Race Condition

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-8565. PoCs published by Metasploit, CodeColorist, timwr, including Metasploit module exploits/osx/local/feedback_assistant_root.

AI-analyzed exploit summary This Metasploit module exploits a race condition in Mac OS X Feedback Assistant (CVE-2019-8565) to achieve local privilege escalation to root. It uploads a payload to a writable directory and executes it via the vulnerability.

Description

A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalmacos
https://www.exploit-db.com/exploits/46914

This Metasploit module exploits a race condition in Mac OS X Feedback Assistant (CVE-2019-8565) to achieve local privilege escalation to root. It uploads a payload to a writable directory and executes it via the vulnerability.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Mac OS X Feedback Assistant (versions before 10.14.4)
No auth needed
Prerequisites: A writable directory on the target system · Non-root session on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by CodeColorist, timwr · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/feedback_assistant_root.rb

This Metasploit module exploits a race condition in Mac OS X Feedback Assistant (CVE-2019-8565) to achieve root privilege escalation. It uploads a payload to a writable directory and executes it via a crafted exploit binary.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Mac OS X Feedback Assistant (versions < 10.14.4)
Auth required
Prerequisites: Local access to a vulnerable Mac OS X system · Non-root session · Writable directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT209599
Vendor Advisory x_refsource_misc
https://support.apple.com/HT209600

Scores

CVSS v3 7.0
EPSS 0.2874
EPSS Percentile 96.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (2)
apple/iphone_os < 12.2
apple/mac_os_x < 10.14.4
Published Dec 18, 2019
Tracked Since Feb 18, 2026