peter bassill · operator
$ cve CVE-2019-8526 JSON

CVE-2019-8526 KEV

7.8
HIGH · CVSS 3.1 · EPSS 0.7% (pctl 51)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-08.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.7% — more likely to be exploited than 51% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2023-05-08
Public exploitnone known
Published2019-12-18
Last modified2026-06-17

CISA KEV

NameApple macOS Use-After-Free Vulnerability
Added2023-04-17
Due2023-05-08
Vendor / productApple / macOS
Ransomware usenone reported

Affected (1)

VendorProduct
applemac os x

References

→ the Explorer  ·  watch your stack  ·  NVD