7.2
CVSSv2

CVE-2019-8526

Published: 18/12/2019 Updated: 20/12/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Github Repositories

A macOS <= 10.14.3 Keychain exploit

KeySteal KeySteal is a macOS &lt;= 10143 Keychain exploit that allows you to access passwords inside the Keychain without a user prompt The vulnerability has been assigned CVE-2019-8526 number KeySteal consists of two parts: KeySteal Daemon: This is a daemon that exploits securityd to get a session that is allowed to access the Keychain without a password prompt KeySt