Memory corruption in Apple iOS - CVE-2019-6218
Published: January 23, 2019 / Updated: January 29, 2019
Vulnerability identifier: #VU17146
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6218
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated attacker to gain elevated privileges.
The weakness exists due to a boundary error in the Kernel component when handling malicious input. A local authenticated attacker can run a specially crafted application, trigger memory corruption and execute arbitrary code with kernel privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to a boundary error in the Kernel component when handling malicious input. A local authenticated attacker can run a specially crafted application, trigger memory corruption and execute arbitrary code with kernel privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Apple iOS
macOS
tvOS
macOS
tvOS
How to mitigate CVE-2019-6218
Update to version 12.1.3.
Apple iOS - update to 12.1.3 16D39
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2