7.5
CVSSv2

CVE-2019-8641

Published: 18/12/2019 Updated: 28/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 761
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An out-of-bounds read was addressed with improved input validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple mac os x

apple tvos

apple watchos

Exploits

When an NSKeyedUnarchiver decodes an object, it first allocates the object using allocWithZone, and then puts the object into a dictionary for temporary objects It then calls the appropriate initWithCoder: on the allocated object If initWithCoder: or any method it calls decodes the same object, its gets back a reference to the original object in ...
During processing of incoming iMessages, attacker controlled data is deserialized using the NSUnarchiver API One of the classes that is allowed to be decoded from the incoming data is NSDictionary However, due to the logic of NSUnarchiver, all subclasses of NSDictionary that also implement secure coding can then be deserialized as well NSSharedK ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10146, Security Update 2019-004 Hig ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-10-29-6 Additional information for APPLE-SA-2019-9-26-3 iOS 13 <!--X-Subject-Header-End--> <!--X-Head-of ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-9-26-1 iOS 1242 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product Security vi ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 124 <!--X-Subject-Header-End--> <!--X-Head-o ...

Github Repositories

iOS安全资料整理(中文)

iOS安全资料整理 iOS安全是一个不错的安全研究方向,但中文的资料与整理还是比较缺乏的,因此开启这个awesome清单,欢迎大家来一起贡献! 书籍📚 《九阴真经·iOS黑客攻防秘籍》,陈德,博客 《 iOS应用逆向与安全之道》,罗巍,网名飘云,“飘云阁安全论坛”创始人 《iOS

The reproduction code for CVE-2019-8641.

CVE-2019-8641 Reproduction This is the reproduction code for CVE-2019-8641 for education purpose only!

Recent Articles

Got a pre-A12 iPhone? Love jailbreaks? Happy Friday! 'Unpatchable tethered Boot ROM exploit' released
The Register • Shaun Nichols in San Francisco • 27 Sep 2019

Coder claims iThings older than two years can be unlocked from Apple's clutches

A programmer claims to have found a way to execute arbitrary code on recent-ish iPhones and iPads, paving the way for full-blown tethered jailbreaks. And, we're told, it is impossible for Apple to block these shenanigans as it involves a vulnerability baked into the devices' immutable Boot ROM. Specifically, the coder, who goes by the handle axi0mX, on Friday said they had built checkm8: "A permanent unpatchable bootrom exploit for hundreds of millions of iOS devices ... Most generations of iPho...

It's 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump
The Register • Shaun Nichols in San Francisco • 23 Jul 2019

20 WebKit flaws among latest batch of bug fixes Patch now before you get your NAS kicked: Iomega storage boxes leave millions of files open to the internet

On Monday Apple released a fresh round of security fixes for a load of its operating systems and applications. The July patch batch addresses vulnerabilities in iOS, MacOS, Safari, watchOS, and tvOS, though many of the updates are for common components across each of the platforms, such as the WebKit browser engine. These should be installed as soon as possible. For iOS, the 12.4 update brings a total of 37 fixes for various components in the mobile operating system. More than half of those CVE-...