Buffer overflow in Apple iOS - CVE-2019-6224

 

Buffer overflow in Apple iOS - CVE-2019-6224

Published: January 23, 2019 / Updated: January 29, 2019


Vulnerability identifier: #VU17152
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6224
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The weakness exists due to a boundary error in the FaceTime component when handling malicious input. A remote attacker can initiate a FaceTime call, trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Apple iOS
watchOS
macOS
tvOS

How to mitigate CVE-2019-6224

Update to version 12.1.3.

Apple iOS - update to 12.1.3 16D39
watchOS - update to 5.1.3
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2

External References

Related Security Bulletins