CVE-2019-8506: Apple Multiple Products Type Confusion Vulnerability
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
Other sources
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
— Launchpad
Processing maliciously crafted web content may lead to arbitrary code execution. A type confusion issue was addressed with improved memory handling.
Reference: https://webkitgtk.org/security/WSA-2019-0002.html https://wpewebkit.org/security/WSA-2019-0002.html
— Red Hat
WebKit. A type confusion issue was addressed with improved memory handling.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.24.0 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.44.2-1~deb11u1Fixed in 2.46.4-1~deb11u1Fixed in 2.46.0-2~deb12u1Fixed in 2.46.4-1~deb12u1Fixed in 2.46.4-1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 12.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 5.2 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 7.11 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.9.4 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 12.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 12.2 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.44.2-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.4-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.0-2~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.4-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.4-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-6203
- CVE-2019-8516
- CVE-2019-8552
- CVE-2019-8542
- CVE-2019-8906
- CVE-2019-7286
- CVE-2019-8553
- CVE-2019-8545
- CVE-2019-5608
- CVE-2019-8547
- CVE-2019-8525
- CVE-2019-8527
- CVE-2019-8528
- CVE-2019-8540
- CVE-2019-8514
- CVE-2019-7293
- CVE-2019-6207
- CVE-2019-8510
- CVE-2019-8532
- CVE-2019-8549
- CVE-2019-8618
- CVE-2019-8531
- CVE-2019-8502
- CVE-2019-8517
- CVE-2019-8551
- CVE-2019-8535
- CVE-2019-6201
- CVE-2019-8518
- CVE-2019-8523
- CVE-2019-8524
- CVE-2019-8558
- CVE-2019-8559
- CVE-2019-8563
- CVE-2019-8638
- CVE-2019-8639
- CVE-2019-8562
- CVE-2019-8515
- CVE-2019-8536
- CVE-2019-8544
- CVE-2019-7285
- CVE-2019-8556
- CVE-2019-8506
- CVE-2019-8503
- CVE-2019-7292
- CVE-2019-8530
- CVE-2019-8538
- CVE-2019-8511
- CVE-2019-8546
- CVE-2019-8548
- CVE-2019-8541
- CVE-2019-6232
- CVE-2019-6236
- CVE-2019-6204
- CVE-2019-8505
- CVE-2019-8512
- CVE-2019-8550
- CVE-2019-8565
- CVE-2019-8521
- CVE-2019-8504
- CVE-2019-8529
- CVE-2019-7284
- CVE-2019-8566
- CVE-2019-8554
- CVE-2019-6222
- CVE-2019-8567
Frequently Asked Questions
What is CVE-2019-8506?
CVE-2019-8506 is a type confusion vulnerability in multiple Apple products, including iOS, tvOS, watchOS, Safari, iTunes for Windows, and iCloud for Windows.
What is the severity of CVE-2019-8506?
The severity of CVE-2019-8506 is critical with a CVSS score of 8.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by processing maliciously crafted web content, which may lead to arbitrary code execution.
Which versions of the affected software are vulnerable?
Versions up to and excluding iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11 are vulnerable.
What is the recommended remedy for CVE-2019-8506?
To fix CVE-2019-8506, users should update to iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, or iCloud for Windows 7.11.