CERT-In Advisory
CIAD-2019-0031
Multiple Vulnerabilities in Apple iOS
Original Issue Date: September 30, 2019
Severity Rating: High
Software Affected
- Apple iOS versions 13,13.1 &iPadOS 13.1 and prior
Overview
Multiple vulnerabilities have been reported in Apple iOS which could allow an attacker to execute arbitrary code, cause denial of service conditions (DoS), obtain potentially sensitive information, bypass security controls, spoof a URL and cause cross site scripting on the targeted system.
Description
These vulnerabilities are caused due to logic issue in the display of notification, memory corruption in the core audio component, an error in face ID component, out-of-bound read, improper state management and improper permission validation while executing commands.
A remote attacker could exploit these vulnerabilities by persuading a user to open a specially crafted web content or malicious application. Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, cause denial of service conditions (DoS), obtain potentially sensitive information, bypass security controls, spoof a URL and cause cross site scripting on the targeted system.
Solution
Upgrade Apple iOS as mentioned at the vendor advisory:
https://support.apple.com/en-in/HT201222
Vendor Information
Apple
https://support.apple.com/en-in/HT210603
https://support.apple.com/en-in/HT210590
https://support.apple.com/en-in/HT210606
References
Apple
https://support.apple.com/en-in/HT210603
https://support.apple.com/en-in/HT210590
https://support.apple.com/en-in/HT210606
CVE Name
CVE-2019-8775
CVE-2019-8641
CVE-2019-8711
CVE-2019-8705
CVE-2019-8760
CVE-2019-8641
CVE-2019-8704
CVE-2019-8742
CVE-2019-8731
CVE-2019-8727
CVE-2019-8674
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|