CVE-2019-8584: Use After Free
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8584
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8593
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8560
- CVE-2019-8633
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8631
- CVE-2019-8568
- CVE-2019-8637
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8574
- CVE-2019-8607
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8612
- CVE-2019-8620
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-8589
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8573
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8569
- CVE-2019-8599
- CVE-2019-8626
- CVE-2019-8613
- CVE-2019-8664
- CVE-2019-8617
- CVE-2019-8630
Frequently Asked Questions
What is CVE-2019-8584?
CVE-2019-8584 is a vulnerability in WebKit that allows arbitrary code execution when processing malicious web content.
Which software versions are affected by CVE-2019-8584?
iOS versions up to and including 12.3, macOS Mojave versions up to and including 10.14.5, tvOS versions up to and including 12.3, Safari versions up to and including 12.1.1, iTunes for Windows versions up to and including 12.9.5, and iCloud for Windows versions up to and including 7.12 are affected by CVE-2019-8584.
How severe is CVE-2019-8584?
CVE-2019-8584 has a severity rating of 8.8, which is considered high.
What is the recommended remedy for CVE-2019-8584?
Update to iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, or iCloud for Windows 7.12 to fix CVE-2019-8584.
Where can I find more information about CVE-2019-8584?
More information about CVE-2019-8584 can be found on the Apple support website.