CVE-2019-8646 is an out-of-bounds read vulnerability affecting Apple's iOS, macOS, tvOS, and watchOS, specifically related to iMessage. This flaw, rated High severity (CVSS 7.5), allows a remote attacker to leak memory due to insufficient input validation. While there is no evidence of active exploitation in the wild, an ExploitDB entry exists detailing a deserialization vulnerability that could be related, and it has garnered significant community discussion and media coverage. Apple addressed this issue in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, and watchOS 5.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 5.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.