CVE-2019-8662

CRITICAL

Apple Iphone OS < 12.4 - Insecure Deserialization

Title source: rule
STIX 2.1

Description

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/47608
exploitdb WRITEUP VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/47189

Scores

CVSS v3 9.8
EPSS 0.1212
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502 CWE-416
Status published
Products (4)
apple/iphone_os < 12.4
apple/mac_os_x < 10.14.6
apple/tvos < 12.4
apple/watchos < 5.3
Published Dec 18, 2019
Tracked Since Feb 18, 2026