CVE-2019-8506: Apple Multiple Products Type Confusion Vulnerability
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
Other sources
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
— Launchpad
Processing maliciously crafted web content may lead to arbitrary code execution. A type confusion issue was addressed with improved memory handling.
Reference: https://webkitgtk.org/security/WSA-2019-0002.html https://wpewebkit.org/security/WSA-2019-0002.html
— Red Hat
WebKit. A type confusion issue was addressed with improved memory handling.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-6203
- CVE-2019-8516
- CVE-2019-8552
- CVE-2019-8542
- CVE-2019-8906
- CVE-2019-7286
- CVE-2019-8553
- CVE-2019-8545
- CVE-2019-5608
- CVE-2019-8547
- CVE-2019-8525
- CVE-2019-8527
- CVE-2019-8528
- CVE-2019-8540
- CVE-2019-8514
- CVE-2019-7293
- CVE-2019-6207
- CVE-2019-8510
- CVE-2019-8532
- CVE-2019-8549
- CVE-2019-8618
- CVE-2019-8531
- CVE-2019-8502
- CVE-2019-8517
- CVE-2019-8551
- CVE-2019-8535
- CVE-2019-6201
- CVE-2019-8518
- CVE-2019-8523
- CVE-2019-8524
- CVE-2019-8558
- CVE-2019-8559
- CVE-2019-8563
- CVE-2019-8638
- CVE-2019-8639
- CVE-2019-8562
- CVE-2019-8515
- CVE-2019-8536
- CVE-2019-8544
- CVE-2019-7285
- CVE-2019-8556
- CVE-2019-8506
- CVE-2019-8503
- CVE-2019-7292
- CVE-2019-8530
- CVE-2019-8538
- CVE-2019-8511
- CVE-2019-8546
- CVE-2019-8548
- CVE-2019-8541
- CVE-2019-6232
- CVE-2019-6236
- CVE-2019-6204
- CVE-2019-8505
- CVE-2019-8512
- CVE-2019-8550
- CVE-2019-8565
- CVE-2019-8521
- CVE-2019-8504
- CVE-2019-8529
- CVE-2019-7284
- CVE-2019-8566
- CVE-2019-8554
- CVE-2019-6222
- CVE-2019-8567
Frequently Asked Questions
What is CVE-2019-8506?
CVE-2019-8506 is a type confusion vulnerability in multiple Apple products, including iOS, tvOS, watchOS, Safari, iTunes for Windows, and iCloud for Windows.
What is the severity of CVE-2019-8506?
The severity of CVE-2019-8506 is critical with a CVSS score of 8.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by processing maliciously crafted web content, which may lead to arbitrary code execution.
Which versions of the affected software are vulnerable?
Versions up to and excluding iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11 are vulnerable.
What is the recommended remedy for CVE-2019-8506?
To fix CVE-2019-8506, users should update to iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, or iCloud for Windows 7.11.