A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT210785 | release notes vendor advisory |
https://support.apple.com/en-us/HT210788 | release notes vendor advisory |
https://support.apple.com/en-us/HT210789 | release notes vendor advisory |
https://support.apple.com/en-us/HT210790 | release notes vendor advisory |