Skip to main content

CVE detail

CVE-2019-8602

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.

CVSS 7.8 · HighBuzz score 31.0

Buzz score

Why this CVE is surfacing

Buzz score total 31.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
11.5
3 sources across 2 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Researchers have uncovered some potentially serious SQLite vulnerabilities and they have demonstrated their findings by hacking an iPhone and a command and control (C&C) server used by malware.

    newswww.securityweek.comAug 13, 2019, 7:45 AM
  • 12th August – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 12th August 2019, please download our Threat Intelligence Bulletin. Top attacks and breaches AT&T employees have been bribed to unlock more than 2 million mobile devices and plant malware on the company’s internal network. The malware allowed the threat actor to gather the […]

    vendorresearch.checkpoint.comAug 12, 2019, 12:34 PM
  • Experts demonstrated that SQLite database can be abused by threat actors as an attack vector to execute malicious code in other apps. Experts at CheckPoint discovered that SQLite database can be abused by threat actors as an attack vector to execute malicious code in other apps, including Apple’s . The experts presented the attack technique at the DEF […]

    newssecurityaffairs.comAug 11, 2019, 4:18 PM
  • SELECT code_execution FROM * USING SQLite;Check Point Research

    Gaining code execution using a malicious SQLite database Research By: Omer Gull tl;dr SQLite is one of the most deployed software in the world. However, from a security perspective, it has only been examined through the lens of WebSQL and browser exploitation. We believe that this is just the tip of the iceberg. In our […]

    vendorresearch.checkpoint.comAug 10, 2019, 9:00 PM
  • Apple released security updates for Windows versions of iTunes and iCloud, to address recently disclosed SQLite and WebKit security flaws. Apple released security updates to address recently disclosed SQLite and WebKit security vulnerabilities affecting Windows versions of iTunes and iCloud. Apple released iTunes for Windows 12.9.5 that addresses a total of 25 flaws, four SQLite […]

    newssecurityaffairs.comJun 1, 2019, 2:34 PM
  • Apple this week released updates for iTunes and iCloud for Windows applications, to address recently disclosed SQLite and WebKit security flaws in them. iTunes for Windows 12.9.5 was released with patches for a total of 25 vulnerabilities. Of these, four impact SQLite, while the remaining 21 were addressed in WebKit.

    newswww.securityweek.comMay 30, 2019, 2:46 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence