CVE-2019-8668: Apple iPhone OS

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. Processing a maliciously crafted image may lead to a denial of service.

Affected products

  • Apple iPhone OS: before 12.4 (fixed in 12.4)
  • Apple tvOS: before 12.4 (fixed in 12.4)
  • Apple watchOS: before 5.3 (fixed in 5.3)

Published 2020-10-27. Last modified 2026-06-17.