CVE-2019-8662 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 9.8% (pctl 95)
Patch early
A public exploit exists.
Description
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.78% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-12-18 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| apple | iphone os |
| apple | mac os x |
| apple | tvos |
| apple | watchos |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address | 2019-11-11 |
| exploit-db | macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances | 2019-07-30 |
References
→ the Explorer · watch your stack · NVD