{"cve":{"cve_id":"CVE-2019-8506","is_kev":true,"kev_date_added":"2022-05-04","kev_vendor_project":"Apple","kev_product":"Multiple Products","kev_vulnerability_name":"Apple Multiple Products Type Confusion Vulnerability","kev_short_description":"A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.","kev_required_action":"Apply updates per vendor instructions.","kev_due_date":"2022-05-25","kev_known_ransomware":false,"kev_notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-8506","kev_cwes":["CWE-843"],"epss_score":0.18172,"epss_percentile":0.9683,"epss_as_of":"2026-06-23","description":"A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.","published_at":"2019-12-18T17:33:16Z","last_modified_at":null,"cvss_v3_score":8.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-843"],"nvd_references":["https://support.apple.com/HT209599","https://support.apple.com/HT209601","https://support.apple.com/HT209603","https://support.apple.com/HT209604","https://support.apple.com/HT209605","https://support.apple.com/HT209602"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-06-28T23:13:02.448718Z"},"effective_severity":"HIGH","badges":["kev"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"icloud-for-windows","product_name":"iCloud for Windows","version_start":"unspecified","version_start_inclusive":true,"version_end":"iCloud for Windows 7.11","version_end_inclusive":false,"cpe23_uri":"cve5:apple:icloud-for-windows:unspecified:iCloud for Windows 7.11"},{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"ios","product_name":"iOS","version_start":"unspecified","version_start_inclusive":true,"version_end":"iOS 12.2","version_end_inclusive":false,"cpe23_uri":"cve5:apple:ios:unspecified:iOS 12.2"},{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"itunes-for-windows","product_name":"iTunes for Windows","version_start":"unspecified","version_start_inclusive":true,"version_end":"iTunes 12.9.4 for Windows","version_end_inclusive":false,"cpe23_uri":"cve5:apple:itunes-for-windows:unspecified:iTunes 12.9.4 for Windows"},{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"safari","product_name":"Safari","version_start":"unspecified","version_start_inclusive":true,"version_end":"Safari 12.1","version_end_inclusive":false,"cpe23_uri":"cve5:apple:safari:unspecified:Safari 12.1"},{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"tvos","product_name":"tvOS","version_start":"unspecified","version_start_inclusive":true,"version_end":"tvOS 12.2","version_end_inclusive":false,"cpe23_uri":"cve5:apple:tvos:unspecified:tvOS 12.2"},{"vendor_slug":"apple","vendor_name":"Apple","product_slug":"watchos","product_name":"watchOS","version_start":"unspecified","version_start_inclusive":true,"version_end":"watchOS 5.2","version_end_inclusive":false,"cpe23_uri":"cve5:apple:watchos:unspecified:watchOS 5.2"}],"exploit_refs":[],"news":[],"references":[{"url":"https://support.apple.com/HT209599","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://support.apple.com/HT209601","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://support.apple.com/HT209603","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://support.apple.com/HT209604","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://support.apple.com/HT209605","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://support.apple.com/HT209602","source_type":"VENDOR_ADVISORY","tags":["advisory"]}],"timeline":[{"type":"published","at":"2019-12-18T17:33:16Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2022-05-04T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-06-24T00:31:24.982914Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:24.982914Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:24.982914Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:24.982914Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:24.982914Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:24.982914Z","label":"CVSS score revised","source":"vulnrichment"}]}