CVE-2019-8835: Critical severity tvos vulnerability
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2 https://webkitgtk.org/security/WSA-2020-0001.html
Other sources
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
— MITRE
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-8835?
CVE-2019-8835 is a vulnerability in WebKit that allows processing maliciously crafted web content to lead to arbitrary code execution.
How severe is CVE-2019-8835?
CVE-2019-8835 has a severity score of 8.8, indicating a critical vulnerability.
Which software versions are affected by CVE-2019-8835?
Safari 13.0.4, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, and iTunes 12.10.3 for Windows are affected by CVE-2019-8835.
How can CVE-2019-8835 be fixed?
To fix CVE-2019-8835, update to the fixed versions: Safari 13.0.4, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, and iTunes 12.10.3 for Windows.
Is there any additional information about CVE-2019-8835?
More information about CVE-2019-8835 can be found at the following references: - [Apple Support Page 1](https://support.apple.com/en-us/HT210785) - [Apple Support Page 2](https://support.apple.com/en-us/HT210793) - [Apple Support Page 3](https://support.apple.com/en-us/HT210790)