CVE-2019-8846: Use After Free
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2 https://webkitgtk.org/security/WSA-2020-0001.html
Other sources
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
— MITRE
WebKit. A use after free issue was addressed with improved memory management.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-8846?
CVE-2019-8846 is a use after free vulnerability in WebKit that can lead to arbitrary code execution.
How does CVE-2019-8846 affect Apple Safari?
CVE-2019-8846 affects Apple Safari version 13.0.4 and earlier, and can be exploited by processing malicious web content.
Is there a fix for CVE-2019-8846?
Yes, CVE-2019-8846 is fixed in Safari 13.0.4 and later versions.
Which other Apple software is affected by CVE-2019-8846?
CVE-2019-8846 also affects iCloud for Windows versions 10.9 and earlier, iOS 13.3 and earlier, iPadOS 13.3 and earlier, iTunes 12.10.3 for Windows, and iCloud for Windows 7.16 and earlier.
What is the severity of CVE-2019-8846?
CVE-2019-8846 has a severity score of 8.8, indicating a critical vulnerability.