CVE-2019-8815: Critical severity tvos vulnerability
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
WebKit Process Model. Multiple memory corruption issues were addressed with improved memory handling.
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8815
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8787
- CVE-2019-8803
- CVE-2019-8785
- CVE-2019-8797
- CVE-2019-8795
- CVE-2019-8798
- CVE-2019-8794
- CVE-2019-8786
- CVE-2019-8829
- CVE-2019-8813
- CVE-2019-8782
- CVE-2019-8783
- CVE-2019-8808
- CVE-2019-8811
- CVE-2019-8812
- CVE-2019-8814
- CVE-2019-8816
- CVE-2019-8819
- CVE-2019-8820
- CVE-2019-8821
- CVE-2019-8822
- CVE-2019-8823
- CVE-2019-8827
- CVE-2019-8815
- CVE-2019-8784
- CVE-2019-8801
- CVE-2019-8796
- CVE-2019-8788
- CVE-2019-8789
- CVE-2017-7152
- CVE-2019-8804
- CVE-2019-8793
- CVE-2019-15126
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8815.
What is the severity of CVE-2019-8815?
The severity of CVE-2019-8815 is critical with a severity value of 8.8.
Which software versions are affected by CVE-2019-8815?
iOS versions up to, but not inclusive of, 13.2, iPadOS versions up to, but not inclusive of, 13.2, iTunes for Windows versions up to, but not inclusive of, 12.10.2, tvOS versions up to, but not inclusive of, 13.2, Safari versions up to, but not inclusive of 13.0.3, and iCloud for Windows versions up to, but not inclusive of, 7.15 are affected by CVE-2019-8815.
How can I fix CVE-2019-8815?
To fix CVE-2019-8815, update your software to iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, or iCloud for Windows 7.15.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-8815?
The Common Weakness Enumeration (CWE) ID for CVE-2019-8815 is CWE-787.