CVE-2019-8624 is an out-of-bounds read vulnerability affecting Apple watchOS, specifically fixed in version 5.3. This flaw, categorized as CWE-125, could allow a remote attacker to leak sensitive memory information due to insufficient input validation. With a CVSS score of 7.5 (High), it presents a significant risk, requiring no user interaction for exploitation and potentially leading to high confidentiality impact. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-47158) exists, and it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.