cve-2019-8605
HIGH CVSS 7.8 opencve
Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
Timeline
- Published
- 2019-12-18 18:15 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
opencve | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
vulnrichment |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2019-8605",
"epss": {
"score": 0.17609
},
"kev": {
"dateAdded": "2022-06-27T00:00:00+00:00",
"dueDate": "2022-07-18T00:00:00+00:00"
},
"mitre": {
"cpes": [],
"created": "2019-12-18T17:33:18+00:00",
"description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2019/8xxx/CVE-2019-8605.json",
"references": [
"https://support.apple.com/HT210118",
"https://support.apple.com/HT210119",
"https://support.apple.com/HT210120",
"https://support.apple.com/HT210122"
],
"title": null,
"updated": "2025-10-21T23:35:55.110000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
],
"created": "2019-12-18T18:15:28.833000+00:00",
"description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.",
"metrics": {
"cvssV2_0": {
"score": 9.3,
"vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2019/CVE-2019-8605.json",
"references": [
"https://support.apple.com/HT210118",
"https://support.apple.com/HT210119",
"https://support.apple.com/HT210120",
"https://support.apple.com/HT210122",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
],
"title": null,
"updated": "2026-06-17T02:42:14.560000+00:00",
"vendors": [
"apple",
"apple$PRODUCT$iphone_os",
"apple$PRODUCT$mac_os_x",
"apple$PRODUCT$tvos",
"apple$PRODUCT$watchos"
],
"weaknesses": [
"CWE-416"
]
},
"opencve": {
"changes": [
{
"created": "2025-01-29T18:15:00+00:00",
"data": [
{
"details": {
"added": {
"kev": {
"dateAdded": "2022-06-27"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "5fb428d7-f38d-404d-ad0a-8051214cf2bb"
},
{
"created": "2025-10-21T19:30:00+00:00",
"data": [
{
"details": {
"added": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
],
"removed": []
},
"type": "references"
}
],
"id": "a977f05e-5a11-4963-a1fa-63aff10e69d9"
},
{
"created": "2025-10-21T20:30:00+00:00",
"data": [
{
"details": {
"added": [],
"removed": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
]
},
"type": "references"
}
],
"id": "4b595f90-faff-4609-85f5-f033089b6206"
},
{
"created": "2025-10-22T00:15:00+00:00",
"data": [
{
"details": {
"added": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
],
"removed": []
},
"type": "references"
}
],
"id": "0f26b4d6-c061-42bd-9a43-7e46a914e4fd"
}
],
"cpes": {
"data": [
"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2019-12-18T17:33:18+00:00",
"provider": "mitre"
},
"description": {
"data": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {
"score": 9.3,
"vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
},
"provider": "nvd"
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"provider": "vulnrichment"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.17609
},
"provider": "first"
},
"kev": {
"data": {
"dateAdded": "2022-06-27T00:00:00+00:00",
"dueDate": "2022-07-18T00:00:00+00:00"
},
"provider": "cisa"
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://support.apple.com/HT210118",
"https://support.apple.com/HT210119",
"https://support.apple.com/HT210120",
"https://support.apple.com/HT210122",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
],
"providers": [
"mitre",
"nvd",
"vulnrichment"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2025-10-23T18:52:17.823000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"apple",
"apple$PRODUCT$iphone_os",
"apple$PRODUCT$mac_os_x",
"apple$PRODUCT$tvos",
"apple$PRODUCT$watchos"
],
"providers": [
"nvd"
]
},
"weaknesses": {
"data": [
"CWE-416"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2019-12-18T17:33:18+00:00",
"description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {},
"kev": {
"dateAdded": "2022-06-27"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605"
],
"title": null,
"updated": "2025-01-29T17:28:20.451000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2019/8xxx/CVE-2019-8605.json",
"weaknesses": [
"CWE-416"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)