Apple Security Advisories · December 2019 — Apple Security Advisories
44 advisories 44 CVEs

Apple-vendor CVEs for 2019-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-19906

OtherPoC exploitHIGH2019-12-19

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in...

CVEs:CVE-2019-19906

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8852

macOSPoC exploitHIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with k...

CVEs:CVE-2019-8852

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8792

iOSPoC exploitCRITICAL2019-12-18

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

CVEs:CVE-2019-8792

Affected products

ProductStatusVendorPackageEcosystem
shazam affected apple — —
Upstream advisory

CVE-2019-8791

iOSPoC exploitMEDIUM2019-12-18

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open re...

CVEs:CVE-2019-8791

Affected products

ProductStatusVendorPackageEcosystem
shazam affected apple — —
Upstream advisory

CVE-2019-8844

iPadOSCoalition ESS 30-63%HIGH2019-12-11

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Proc...

CVEs:CVE-2019-8844

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8835

iPadOSCoalition ESS 30-63%HIGH2019-12-11

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciou...

CVEs:CVE-2019-8835

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2019-8846

iPadOSCoalition ESS < 30%HIGH2019-12-11

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafte...

CVEs:CVE-2019-8846

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2019-8849

OtherCoalition ESS < 30%CRITICAL2019-12-18

The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.

CVEs:CVE-2019-8849

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_ssl affected apple — —
Upstream advisory

CVE-2019-8830

iPadOSCoalition ESS < 30%HIGH2019-12-11

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4...

CVEs:CVE-2019-8830

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8842

macOSCoalition ESS < 30%CRITICAL2019-12-11

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit ...

CVEs:CVE-2019-8842

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8723

XcodeCoalition ESS < 30%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8723

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8724

XcodeCoalition ESS < 30%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8724

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8721

XcodeCoalition ESS < 30%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8721

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8722

XcodeCoalition ESS < 30%HIGH2019-12-18

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

CVEs:CVE-2019-8722

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8832

iPadOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8832

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8833

iPadOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An ap...

CVEs:CVE-2019-8833

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8838

iPadOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8838

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8836

iPadOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-8836

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8847

macOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with k...

CVEs:CVE-2019-8847

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8840

XcodeCoalition ESS < 30%CRITICAL2019-12-11

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

CVEs:CVE-2019-8840

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8828

iPadOSCoalition ESS < 30%HIGH2019-12-11

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An appl...

CVEs:CVE-2019-8828

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8632

OtherCoalition ESS < 30%HIGH2019-12-18

Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be ab...

CVEs:CVE-2019-8632

Affected products

ProductStatusVendorPackageEcosystem
texture affected apple — —
Upstream advisory

CVE-2019-8837

macOSCoalition ESS < 30%HIGH2019-12-11

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A malicious application may be able to access restricted files.

CVEs:CVE-2019-8837

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8711

iOSCoalition ESS < 30%MEDIUM2019-12-18

A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This issue is fixed in iOS 13. Notification previews may show on Bluetooth accessories even when previews are disabled.

CVEs:CVE-2019-8711

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2019-8848

iPadOSCoalition ESS < 30%HIGH2019-12-11

This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes...

CVEs:CVE-2019-8848

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8800

XcodeCoalition ESS < 30%CRITICAL2019-12-18

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8800

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8806

XcodeCoalition ESS < 30%CRITICAL2019-12-18

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8806

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8739

XcodeCoalition ESS < 30%CRITICAL2019-12-18

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8739

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8738

XcodeCoalition ESS < 30%CRITICAL2019-12-18

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2019-8738

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple — —
Upstream advisory

CVE-2019-8727

iOSCoalition ESS < 30%MEDIUM2019-12-18

A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2019-8727

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2019-14899

macOSCoalition ESS < 30%HIGH2019-12-11

A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting...

CVEs:CVE-2019-14899

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2019-8853

macOSCoalition ESS < 30%MEDIUM2019-12-11

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Securi...

CVEs:CVE-2019-8853

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8725

SafariCoalition ESS < 30%MEDIUM2019-12-18

The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.

CVEs:CVE-2019-8725

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2019-8654

SafariCoalition ESS < 30%MEDIUM2019-12-18

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.

CVEs:CVE-2019-8654

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2019-8731

iOSCoalition ESS < 30%MEDIUM2019-12-18

A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disclose user information.

CVEs:CVE-2019-8731

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2019-8839

macOSCoalition ESS < 30%HIGH2019-12-11

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An attacker in a privileged position may be able to perform a denia...

CVEs:CVE-2019-8839

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2019-8856

iPadOSCoalition ESS < 30%HIGH2019-12-11

An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mo...

CVEs:CVE-2019-8856

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2019-8841

iPadOSCoalition ESS < 30%CRITICAL2019-12-11

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-8841

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2019-8760

iOSCoalition ESS < 30%MEDIUM2019-12-18

This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

CVEs:CVE-2019-8760

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2019-8704

tvOSCoalition ESS < 30%MEDIUM2019-12-18

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

CVEs:CVE-2019-8704

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2019-8857

iPadOSCoalition ESS < 30%LOW2019-12-11

The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.

CVEs:CVE-2019-8857

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2019-8742

iOSCoalition ESS < 30%LOW2019-12-18

The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with physical access to an iOS device may be able to access contacts from the lock screen.

CVEs:CVE-2019-8742

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

CVE-2019-8548

watchOSCoalition ESS < 30%LOW2019-12-18

An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clea...

CVEs:CVE-2019-8548

Affected products

ProductStatusVendorPackageEcosystem
watchos affected apple — —
Upstream advisory

CVE-2012-6094

OtherEPSS <= 49%CRITICAL2019-12-20

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

CVEs:CVE-2012-6094

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.