CVE-2019-8765 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 6.93% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-12-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apple | watchos |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JavaScriptCore - GetterSetter Type Confusion During DFG Compilation | 2019-10-30 |
References
→ the Explorer · watch your stack · NVD