PT-2021-9124 · Apple · Ios+2
Min (Spark) Zheng
+1
·
Published
2021-12-23
·
Updated
2022-01-05
·
CVE-2019-8702
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 10.14.6
Security Update versions prior to 2019-004 High Sierra
Security Update versions prior to 2019-004 Sierra
iOS versions prior to 12.4
tvOS versions prior to 12.4
Description
A local user may be able to read a persistent account identifier. This issue was addressed with a new entitlement.
Recommendations
For macOS versions prior to 10.14.6, update to macOS Mojave 10.14.6.
For Security Update versions prior to 2019-004 High Sierra, apply Security Update 2019-004.
For Security Update versions prior to 2019-004 Sierra, apply Security Update 2019-004 Sierra.
For iOS versions prior to 12.4, update to iOS 12.4.
For tvOS versions prior to 12.4, update to tvOS 12.4.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ios
Apple Macos
Tvos