CVE-2019-8844: Critical severity tvos vulnerability
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2 https://webkitgtk.org/security/WSA-2020-0001.html
Other sources
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
— MITRE
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-8844?
CVE-2019-8844 is a vulnerability in WebKit that allows for multiple memory corruption issues.
What is the severity of CVE-2019-8844?
CVE-2019-8844 has a severity rating of 8.8, which is considered critical.
Which software versions are affected by CVE-2019-8844?
Safari 13.0.4, iCloud for Windows 10.9, and WebKitGTK 2.26.3 are affected by CVE-2019-8844.
How can I fix CVE-2019-8844?
To fix CVE-2019-8844, update to the fixed versions of Safari, iCloud for Windows, and WebKitGTK.
Where can I find more information about CVE-2019-8844?
You can find more information about CVE-2019-8844 on the Apple support website.