CVE-2019-8825: Apple iCloud
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 10.7, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected products
- Apple iCloud: before 7.14 (fixed in 7.14); from 10.0, before 10.7 (fixed in 10.7)
- Apple iPhone OS: before 13.3 (fixed in 13.3)
- Apple iTunes: before 12.10.1 (fixed in 12.10.1)
- Apple Mac OS X: before 10.15.1 (fixed in 10.15.1)
Published 2020-10-27. Last modified 2026-06-17.