CVE-2019-8664: Apple iPhone OS

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.

Affected products

  • Apple iPhone OS: before 12.3 (fixed in 12.3)
  • Apple watchOS: before 5.2.1 (fixed in 5.2.1)

Published 2020-10-27. Last modified 2026-06-17.