CVE-2019-8660 is a critical memory corruption vulnerability affecting Apple's iOS, macOS, tvOS, and watchOS. It stems from insufficient input validation, allowing a remote attacker to trigger unexpected application termination or achieve arbitrary code execution. With a CVSS score of 9.8 (Critical), this vulnerability requires no user interaction or prior authentication, making it highly severe. While not listed in CISA's KEV catalog, public exploit code exists (EDB-47193) and it has garnered significant community discussion and media coverage, including reports of its use to read files on iPhones.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 12.4CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 5.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.