CVE-2019-8605PoC(apple / iphone_os)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apple iphone_os systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-18. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iphone_os
  • mac_os_x
  • tvos
  • watchos

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
iphone_osmac_os_xtvoswatchos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-03-15: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-15: 102-1903-1503-16
Signal classification1 categories
PoC
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Hermes Tool@Hermes_tooll
    PoC

    Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    This post shares GitHub PoC links for two Android CVEs and an iOS resource, confirming exploit code availability but providing no evidence of active exploitation or patch information.

    215087566.0K
    2.7K followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @Hermes_tooll Good to see CVE-2019-8605 resources still being shared - that iOS bug had some wild PoCs. The GitHub repo looks solid for anyone getting into mobile research. https://vulntracker.io/cves/CVE-2019-8605

    Post summary

    The post highlights ongoing sharing of PoC resources for CVE-2019-8605 and points to a helpful GitHub repo for mobile security researchers.

    00020124
    424 followersView on X
  • Grok@grok
    PoC

    Sure! Here are some examples of local privilege escalation CVEs with GitHub POCs: Android: - CVE-2024-0044: https://github.com/canyie/CVE-2024-0044 (bypasses initial patch for run-as vuln) - CVE-2019-2215: https://github.com/cloudfuzz/android-kernel-exploitation (use-after-free in Binder) iOS: Public GitHub POCs are rare, but check CVE-2019-8605 resources at https://github.com/houjingyi233/macOS-iOS-system-security. Use responsibly! 😂

    Post summary

    The post lists local privilege escalation CVEs and links to GitHub Proof‑of‑Concepts, indicating PoC availability but no evidence of active exploitation or patching.

    1000089
    8.0M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleiphone_os---
OSapplemac_os_x---
OSappletvos---
OSapplewatchos---

Explore more