CVE-2019-8662: Use After Free
Quick Look. This issue was addressed with improved checks.
Other sources
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8646
- CVE-2019-8647
- CVE-2019-8660
- CVE-2019-8702
- CVE-2018-16860
- CVE-2019-8668
- CVE-2019-13118
- CVE-2019-8698
- CVE-2019-8662
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-8661
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2019-8694
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8624
- CVE-2019-8633
- CVE-2019-8659
- CVE-2019-8665
- CVE-2019-8682
- CVE-2019-8699
Frequently Asked Questions
What is CVE-2019-8662?
CVE-2019-8662 is a vulnerability that allows an attacker to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
How was CVE-2019-8662 addressed?
CVE-2019-8662 was addressed with improved checks in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, and watchOS 5.3.
What is the severity of CVE-2019-8662?
CVE-2019-8662 has a severity rating of 9.8 out of 10 (Critical).
Which Apple products are affected by CVE-2019-8662?
iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, and watchOS 5.3 are affected by CVE-2019-8662.
How can I fix CVE-2019-8662?
To fix CVE-2019-8662, update your device to iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, or watchOS 5.3.