8.8
CVSSv3

CVE-2019-6200

Published: 05/03/2019 Updated: 06/03/2019
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple mac os x

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-1-22-2 macOS Mojave 10143, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra macOS Mojave 10143, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra are now available and addresses the following: AppleKeyStore Available for: macOS Mojave 1014 ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-1-22-1 iOS 1213 iOS 1213 is now available and addresses the following: AppleKeyStore Available for: iPhone 5s and later, iPad Air and later, and iPod touch 6th generation Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A memory corruption is ...

Recent Articles

Plug in your iPhone, iPad, iPod, fire up the App Store: You have new Apple patches to install
The Register • Shaun Nichols in San Francisco • 23 Jan 2019

Open the door, get on the floor – not so fast if you've an iPhone 4 Old bugs, new bugs, red bugs … yes, it's Oracle mega-update day again

Apple has emitted a handful of software patches to address security vulnerabilities in iOS, macOS, and various peripherals. The round of updates includes a number of fixes for critical flaws in WebKit, FaceTime, and Mac and iThing kernels. For iOS handhelds, the update is billed as iOS 12.1.3. It applies to iPhone 5s and newer, iPad Air and newer, and iPod Touch 6th generation devices. Fixes for the mobile OS include a man-in-the-middle code execution flaw over Bluetooth (CVE-2019-6200), a remot...