CVE-2019-8647 is a critical use-after-free vulnerability affecting Apple's iOS, tvOS, and watchOS, specifically within iMessage. This flaw allows a remote attacker to achieve arbitrary code execution due to improved memory management not being implemented. With a CVSS score of 9.8, it presents a severe risk, as it can be exploited remotely without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV, an ExploitDB entry exists detailing an iMessage deserialization vulnerability, and the CVE has garnered significant community discussion and media coverage, indicating high interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 5.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.