CVE-2019-8602 describes a memory corruption vulnerability, specifically a heap-based buffer overflow (CWE-787), that affected multiple Apple products including iOS, macOS, tvOS, watchOS, iTunes for Windows, and iCloud for Windows. This flaw could allow a malicious application to elevate privileges on an affected system. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it garnered significant community discussion and media coverage at the time of its disclosure. Apple addressed the issue by removing the vulnerable code in subsequent updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.12CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
>= 10.0, < 10.4CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
< 12.9.5CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 12.1.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 12.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.