CVE-2019-6235: Apple iPhone OS
Critical severity, CVSS 10.0. EPSS: 2.1% chance of exploitation in the next 30 days.
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
Affected products
- Apple iPhone OS: before 12.1.3 (fixed in 12.1.3)
- Apple iTunes: before 12.9.3 (fixed in 12.9.3)
- Apple Mac OS X: before 10.14.3 (fixed in 10.14.3)
- Apple Tv OS: before 12.1.2 (fixed in 12.1.2)
- Apple Watch OS: before 5.1.3 (fixed in 5.1.3)
Published 2019-03-04. Last modified 2026-06-17.