CVE-2019-8704: Apple iPhone OS

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

Affected products

  • Apple iPhone OS: before 13.0 (fixed in 13.0)
  • Apple tvOS: before 13 (fixed in 13)

Published 2019-12-18. Last modified 2026-06-17.