Apple Security Advisories · November 2019 — Apple Security Advisories
5 advisories 5 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2019-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-8771

iOSExploitedVulnCheck KEV listedCRITICAL2019-11-25

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.

CVEs:CVE-2019-8771

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2019-8696

macOSPoC exploitHIGH2019-11-21

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute...

CVEs:CVE-2019-8696

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8675

macOSPoC exploitHIGH2019-11-21

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute...

CVEs:CVE-2019-8675

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8674

iOSCoalition ESS < 30%CRITICAL2019-11-25

A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.

CVEs:CVE-2019-8674

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
safari affected apple — —
Upstream advisory

CVE-2019-9536

iOSCoalition ESS < 30%MEDIUM2019-11-22

Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.

CVEs:CVE-2019-9536

Affected products

ProductStatusVendorPackageEcosystem
iphone_3gs affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.