CVE-2019-8577
HIGHApple iCloud < 7.12 - Memory Corruption via Improper Input Validation
Title source: llmDescription
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. An application may be able to gain elevated privileges.
References (8)
Core 8
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210118
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210119
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210120
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210124
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210125
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210212
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210122
Various Sources x_refsource_misc
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/
Scores
CVSS v3
7.8
EPSS
0.1026
EPSS Percentile
95.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (7)
apple/icloud
< 7.12
apple/iphone_os
< 12.3
apple/itunes
< 12.9.5
apple/mac_os_x
< 10.14.5
apple/safari
< 12.1.1
apple/tvos
< 12.3
apple/watchos
< 5.2.1
Published
Dec 18, 2019
Tracked Since
Feb 18, 2026