CVE-2019-8554: Medium severity apple ios and ipados vulnerability
Safari. A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions.
Other sources
A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-6203
- CVE-2019-8538
- CVE-2019-8516
- CVE-2019-8552
- CVE-2019-8511
- CVE-2019-8542
- CVE-2019-8512
- CVE-2019-8550
- CVE-2019-8565
- CVE-2019-8521
- CVE-2019-8906
- CVE-2019-8553
- CVE-2019-8545
- CVE-2019-8504
- CVE-2019-8529
- CVE-2019-5608
- CVE-2019-8547
- CVE-2019-8525
- CVE-2019-8527
- CVE-2019-8528
- CVE-2019-8514
- CVE-2019-8540
- CVE-2019-7293
- CVE-2019-6207
- CVE-2019-8510
- CVE-2019-7284
- CVE-2019-8532
- CVE-2019-8546
- CVE-2019-8549
- CVE-2019-8541
- CVE-2019-8566
- CVE-2019-8554
- CVE-2019-6204
- CVE-2019-8505
- CVE-2019-8618
- CVE-2019-8531
- CVE-2019-8502
- CVE-2019-8517
- CVE-2019-8551
- CVE-2019-8535
- CVE-2019-6201
- CVE-2019-8518
- CVE-2019-8523
- CVE-2019-8524
- CVE-2019-8558
- CVE-2019-8559
- CVE-2019-8563
- CVE-2019-8638
- CVE-2019-8639
- CVE-2019-8562
- CVE-2019-6222
- CVE-2019-8515
- CVE-2019-8536
- CVE-2019-8544
- CVE-2019-7285
- CVE-2019-8556
- CVE-2019-8506
- CVE-2019-8503
- CVE-2019-7292
- CVE-2019-8567
- CVE-2019-8530
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8554.
What is the severity of CVE-2019-8554?
The severity of CVE-2019-8554 is medium with a CVSS score of 6.5.
What is the affected software?
The affected software is Apple iOS up to version 12.2 and Apple iPhone OS up to version 12.2.
What is the risk of this vulnerability?
The vulnerability allows a website to access sensor information without user consent, posing a risk to user privacy.
How can I fix CVE-2019-8554?
To fix CVE-2019-8554, update your Apple device to iOS 12.2 or later.