CVE-2019-8747: Critical severity tvos vulnerability

Published Sep 24, 2019
·
Updated

AppleFirmwareUpdateKext. A memory corruption vulnerability was addressed with improved locking.

Other sources

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.

Credit

Mohamed Ghannam@@_simo36, Mohamed Ghannam@@_simo36, Mohamed Ghannam@@_simo36

Affected Software

5 affected componentsFixes available
Apple tvOS<13
13
Apple WatchOS<6.1
6.1
Apple WatchOS<6.1
Apple iOS<13.1
13.1
Apple iPadOS<13.1
13.1

Event History

Dec 18, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-8747?

The severity of CVE-2019-8747 is critical with a CVSS score of 7.8.

2

Which Apple products are affected by CVE-2019-8747?

CVE-2019-8747 affects watchOS (up to version 6.1), tvOS (up to version 13), iOS (up to version 13.1), and iPadOS (up to version 13.1).

3

How can an attacker exploit the vulnerability in CVE-2019-8747?

An attacker can exploit CVE-2019-8747 by executing arbitrary code with kernel privileges.

4

How can I fix CVE-2019-8747?

CVE-2019-8747 is fixed in watchOS 6.1. Ensure you have updated to the latest version of watchOS or the affected software.

5

Where can I find more information about CVE-2019-8747?

You can find more information about CVE-2019-8747 on the Apple support page: https://support.apple.com/en-us/HT210724

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203