Apple Security Advisories · December 2019 — Apple Security Advisories
44 advisories 44 CVEs

Apple-vendor CVEs for 2019-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-19906

OtherPoC exploitHIGH2019-12-19

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in...

CVEs:CVE-2019-19906

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-8852

macOSPoC exploitHIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with k...

CVEs:CVE-2019-8852

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8792

iOSPoC exploitCRITICAL2019-12-18

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

CVEs:CVE-2019-8792

Affected products

ProductStatusVendorPackageEcosystem
shazam affected apple
Upstream advisory

CVE-2019-8791

iOSPoC exploitMEDIUM2019-12-18

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open re...

CVEs:CVE-2019-8791

Affected products

ProductStatusVendorPackageEcosystem
shazam affected apple
Upstream advisory

CVE-2019-8846

iPadOSEPSS <= 49%HIGH2019-12-11

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafte...

CVEs:CVE-2019-8846

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2019-8830

iPadOSEPSS <= 49%HIGH2019-12-11

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4...

CVEs:CVE-2019-8830

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8849

OtherEPSS <= 49%CRITICAL2019-12-18

The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.

CVEs:CVE-2019-8849

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_ssl affected apple
Upstream advisory

CVE-2019-8844

iPadOSEPSS <= 49%HIGH2019-12-11

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Proc...

CVEs:CVE-2019-8844

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8835

iPadOSEPSS <= 49%HIGH2019-12-11

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciou...

CVEs:CVE-2019-8835

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2012-6094

OtherEPSS <= 49%CRITICAL2019-12-20

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

CVEs:CVE-2012-6094

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2019-8842

macOSEPSS <= 49%CRITICAL2019-12-11

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit ...

CVEs:CVE-2019-8842

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8723

XcodeEPSS <= 49%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8723

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8724

XcodeEPSS <= 49%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8724

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8721

XcodeEPSS <= 49%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8721

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8722

XcodeEPSS <= 49%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8722

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8832

iPadOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8832

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8833

iPadOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An ap...

CVEs:CVE-2019-8833

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8838

iPadOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8838

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8836

iPadOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-8836

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8847

macOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with k...

CVEs:CVE-2019-8847

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8840

XcodeEPSS <= 49%CRITICAL2019-12-11

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

CVEs:CVE-2019-8840

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8828

iPadOSEPSS <= 49%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8828

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8632

OtherEPSS <= 49%HIGH2019-12-18

Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be ab...

CVEs:CVE-2019-8632

Affected products

ProductStatusVendorPackageEcosystem
texture affected apple
Upstream advisory

CVE-2019-8837

macOSEPSS <= 49%HIGH2019-12-11

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A malicious application may be able to access restricted files.

CVEs:CVE-2019-8837

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8711

iOSEPSS <= 49%MEDIUM2019-12-18

A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This issue is fixed in iOS 13. Notification previews may show on Bluetooth accessories even when previews are disabled.

CVEs:CVE-2019-8711

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-8848

iPadOSEPSS <= 49%HIGH2019-12-11

This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes...

CVEs:CVE-2019-8848

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2019-8800

XcodeEPSS <= 49%CRITICAL2019-12-18

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8800

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8806

XcodeEPSS <= 49%CRITICAL2019-12-18

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8806

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8739

XcodeEPSS <= 49%CRITICAL2019-12-18

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8739

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8738

XcodeEPSS <= 49%CRITICAL2019-12-18

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8738

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2019-8727

iOSEPSS <= 49%MEDIUM2019-12-18

A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2019-8727

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-14899

macOSEPSS <= 49%HIGH2019-12-11

A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting...

CVEs:CVE-2019-14899

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2019-8853

macOSEPSS <= 49%MEDIUM2019-12-11

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Securi...

CVEs:CVE-2019-8853

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8725

SafariEPSS <= 49%MEDIUM2019-12-18

The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.

CVEs:CVE-2019-8725

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2019-8654

SafariEPSS <= 49%MEDIUM2019-12-18

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.

CVEs:CVE-2019-8654

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2019-8731

iOSEPSS <= 49%MEDIUM2019-12-18

A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disclose user information.

CVEs:CVE-2019-8731

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-8839

macOSEPSS <= 49%HIGH2019-12-11

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An attacker in a privileged position may be able to perform a denia...

CVEs:CVE-2019-8839

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2019-8856

iPadOSEPSS <= 49%HIGH2019-12-11

An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mo...

CVEs:CVE-2019-8856

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2019-8841

iPadOSEPSS <= 49%CRITICAL2019-12-11

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-8841

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2019-8760

iOSEPSS <= 49%MEDIUM2019-12-18

This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

CVEs:CVE-2019-8760

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-8704

tvOSEPSS <= 49%MEDIUM2019-12-18

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

CVEs:CVE-2019-8704

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2019-8857

iPadOSEPSS <= 49%LOW2019-12-11

The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.

CVEs:CVE-2019-8857

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2019-8742

iOSEPSS <= 49%LOW2019-12-18

The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with physical access to an iOS device may be able to access contacts from the lock screen.

CVEs:CVE-2019-8742

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2019-8548

watchOSEPSS <= 49%LOW2019-12-18

An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clea...

CVEs:CVE-2019-8548

Affected products

ProductStatusVendorPackageEcosystem
watchos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.