Apple Security Advisories · February 2019 — Apple Security Advisories
7 advisories 7 CVEs 3 EXPLOITED

Apple-vendor CVEs for 2019-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-7286

macOSExploitedCISA KEV listedCRITICAL2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

CVEs:CVE-2019-7286

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-7287

iOSExploitedCISA KEV listedHIGH2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-7287

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-6223

macOSExploitedCISA KEV listedHIGH2019-02-08

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to ca...

CVEs:CVE-2019-6223

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-7288

macOSEPSS <= 49%CRITICAL2019-02-08

The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .

CVEs:CVE-2019-7288

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-7290

OtherEPSS <= 49%CRITICAL2019-02-08

An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2019-7290

Affected products

ProductStatusVendorPackageEcosystem
shortcuts affected apple
Upstream advisory

CVE-2019-8906

OtherEPSS <= 49%MEDIUM2019-02-18

do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

CVEs:CVE-2019-8906

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-7289

OtherEPSS <= 49%MEDIUM2019-02-08

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Shortcuts 2.1.3 for iOS. A local user may be able to view senstive user information.

CVEs:CVE-2019-7289

Affected products

ProductStatusVendorPackageEcosystem
shortcuts affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.