Apple Security Advisories · January 2019 — Apple Security Advisories
66 advisories 66 CVEs 8 EXPLOITED

Apple-vendor CVEs for 2019-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-6225

tvOSExploitedCISA KEV listedCRITICAL2019-01-23

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.

CVEs:CVE-2019-6225

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2019-6224

watchOSExploitedCISA KEV listedCRITICAL2019-01-23

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.

CVEs:CVE-2019-6224

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
watchos affected apple
Upstream advisory

CVE-2019-6218

tvOSExploitedCISA KEV listedHIGH2019-01-23

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-6218

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2019-6213

watchOSExploitedCISA KEV listedHIGH2019-01-23

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-6213

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
watchos affected apple
Upstream advisory

CVE-2019-6205

tvOSExploitedCISA KEV listedCRITICAL2019-01-23

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

CVEs:CVE-2019-6205

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2019-6214

watchOSExploitedCISA KEV listedHIGH2019-01-23

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

CVEs:CVE-2019-6214

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
watchos affected apple
Upstream advisory

CVE-2019-6208

tvOSExploitedCISA KEV listedHIGH2019-01-23

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

CVEs:CVE-2019-6208

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
Upstream advisory

CVE-2018-4404

macOSExploitedVulnCheck KEV listedHIGH2019-01-11

In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.

CVEs:CVE-2018-4404

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-6215

tvOSWeaponized exploitCRITICAL2019-01-22

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code...

CVEs:CVE-2019-6215

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6209

watchOSWeaponized exploitMEDIUM2019-01-23

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able...

CVEs:CVE-2019-6209

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
watchos affected apple
Upstream advisory

CVE-2019-6219

watchOSActive exploitation (sightings)HIGH2019-01-23

A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. Processing a maliciously crafted message may lead to a denial of service.

CVEs:CVE-2019-6219

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2019-6235

watchOSActive exploitation (sightings)CRITICAL2019-01-23

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2019-6235

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tv_os affected apple
watch_os affected apple
Upstream advisory

CVE-2019-6227

watchOSActive exploitation (sightings)CRITICAL2019-01-22

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead...

CVEs:CVE-2019-6227

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6210

watchOSActive exploitation (sightings)HIGH2019-01-23

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-6210

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tv_os affected apple
watchos affected apple
Upstream advisory

CVE-2019-6231

watchOSActive exploitation (sightings)MEDIUM2019-01-23

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.

CVEs:CVE-2019-6231

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4452

macOSActive exploitation (sightings)HIGH2019-01-23

A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra, macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Secu...

CVEs:CVE-2018-4452

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-6211

macOSActive exploitation (sightings)CRITICAL2019-01-23

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2019-6211

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-6230

watchOSActive exploitation (sightings)HIGH2019-01-23

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

CVEs:CVE-2019-6230

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6202

watchOSActive exploitation (sightings)HIGH2019-01-23

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges.

CVEs:CVE-2019-6202

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2019-6221

macOSActive exploitation (sightings)HIGH2019-01-23

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.

CVEs:CVE-2019-6221

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-6220

macOSActive exploitation (sightings)MEDIUM2019-01-23

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.3. An application may be able to read restricted memory.

CVEs:CVE-2019-6220

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-6200

macOSActive exploitation (sightings)HIGH2019-01-23

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.

CVEs:CVE-2019-6200

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2018-4467

macOSActive exploitation (sightings)CRITICAL2019-01-23

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra, macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Secu...

CVEs:CVE-2018-4467

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4185

watchOSPoC exploitHIGH2019-01-11

In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.

CVEs:CVE-2018-4185

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4180

macOSPoC exploitHIGH2019-01-11

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVEs:CVE-2018-4180

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4181

macOSPoC exploitMEDIUM2019-01-11

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVEs:CVE-2018-4181

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4208

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

CVEs:CVE-2018-4208

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4209

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

CVEs:CVE-2018-4209

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4212

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

CVEs:CVE-2018-4212

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4207

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

CVEs:CVE-2018-4207

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4213

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

CVEs:CVE-2018-4213

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4210

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.

CVEs:CVE-2018-4210

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2018-4194

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2018-4194

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2019-6212

tvOSEPSS <= 49%CRITICAL2019-01-22

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to ar...

CVEs:CVE-2019-6212

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2019-6216

watchOSEPSS <= 49%CRITICAL2019-01-23

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content...

CVEs:CVE-2019-6216

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6226

watchOSEPSS <= 49%CRITICAL2019-01-23

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content...

CVEs:CVE-2019-6226

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6217

watchOSEPSS <= 49%CRITICAL2019-01-22

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content...

CVEs:CVE-2019-6217

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-6234

tvOSEPSS <= 49%CRITICAL2019-01-22

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary c...

CVEs:CVE-2019-6234

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2019-6233

tvOSEPSS <= 49%CRITICAL2019-01-22

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary c...

CVEs:CVE-2019-6233

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2018-4189

watchOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory hand...

CVEs:CVE-2018-4189

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4147

iOSEPSS <= 49%CRITICAL2019-01-11

In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.

CVEs:CVE-2018-4147

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2019-6206

iOSEPSS <= 49%CRITICAL2019-01-23

An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared.

CVEs:CVE-2019-6206

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2016-4642

tvOSEPSS <= 49%MEDIUM2019-01-11

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

CVEs:CVE-2016-4642

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os affected apple
Upstream advisory

CVE-2016-4644

tvOSEPSS <= 49%MEDIUM2019-01-11

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types wit...

CVEs:CVE-2016-4644

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os affected apple
Upstream advisory

CVE-2018-4298

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permissions issue existed in Remote Management. This issue was addressed through improved permission validation.

CVEs:CVE-2018-4298

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2018-4169

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2018-4169

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4254

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation.

CVEs:CVE-2018-4254

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4257

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.

CVEs:CVE-2018-4257

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4258

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.

CVEs:CVE-2018-4258

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2016-4643

tvOSEPSS <= 49%MEDIUM2019-01-11

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.

CVEs:CVE-2016-4643

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
iphone_os affected apple
mac_os affected apple
Upstream advisory

CVE-2019-6229

tvOSEPSS <= 49%CRITICAL2019-01-22

A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to universal cross site scripting.

CVEs:CVE-2019-6229

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2017-13889

macOSEPSS <= 49%CRITICAL2019-01-11

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.

CVEs:CVE-2017-13889

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4186

SafariEPSS <= 49%HIGH2019-01-11

In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.

CVEs:CVE-2018-4186

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2018-4217

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

CVEs:CVE-2018-4217

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2016-7576

iOSEPSS <= 49%HIGH2019-01-11

In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.

CVEs:CVE-2016-7576

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-6228

iOSEPSS <= 49%CRITICAL2019-01-23

A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.

CVEs:CVE-2019-6228

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2017-13886

macOSEPSS <= 49%MEDIUM2019-01-11

In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was addressed with additional restrictions.

CVEs:CVE-2017-13886

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-13887

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.

CVEs:CVE-2017-13887

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-13888

iOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

CVEs:CVE-2017-13888

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-13891

iOSEPSS <= 49%MEDIUM2019-01-11

In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

CVEs:CVE-2017-13891

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2017-2411

iOSEPSS <= 49%HIGH2019-01-11

In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

CVEs:CVE-2017-2411

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2018-4182

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.

CVEs:CVE-2018-4182

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4183

macOSEPSS <= 49%HIGH2019-01-11

In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.

CVEs:CVE-2018-4183

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4179

macOSEPSS <= 49%MEDIUM2019-01-11

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVEs:CVE-2018-4179

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4255

macOSEPSS <= 49%MEDIUM2019-01-11

In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2018-4255

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2018-4256

macOSEPSS <= 49%MEDIUM2019-01-11

In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2018-4256

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.