CVE-2019-8646
CVE-2019-8646
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 11.3%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
30 Jul 2019Public PoC
18 Dec 2019Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.
public PoCs found — 1
exploitdbwww.exploit-db.com/exploits/47194unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →