CVE-2019-8506

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
References
Link Resource
https://support.apple.com/HT209599 Release Notes Vendor Advisory
https://support.apple.com/HT209601 Release Notes Vendor Advisory
https://support.apple.com/HT209602 Release Notes Vendor Advisory
https://support.apple.com/HT209603 Release Notes Vendor Advisory
https://support.apple.com/HT209604 Release Notes Vendor Advisory
https://support.apple.com/HT209605 Release Notes Vendor Advisory
https://support.apple.com/HT209599 Release Notes Vendor Advisory
https://support.apple.com/HT209601 Release Notes Vendor Advisory
https://support.apple.com/HT209602 Release Notes Vendor Advisory
https://support.apple.com/HT209603 Release Notes Vendor Advisory
https://support.apple.com/HT209604 Release Notes Vendor Advisory
https://support.apple.com/HT209605 Release Notes Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8506 US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-18 18:15

Updated : 2025-10-23 18:52


NVD link : CVE-2019-8506

Mitre link : CVE-2019-8506

CVE.ORG link : CVE-2019-8506


JSON object : View

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux_server
  • enterprise_linux_workstation

apple

  • itunes
  • watchos
  • iphone_os
  • icloud
  • safari
  • tvos
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')