KLA11603
Multiple vulnerabilities in Apple iCloud
Updated: 11/15/2019
Detect date
?
10/30/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Apple iCloud. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in libxslt can be exploited remotely to execute arbitrary code;
  2. Multiple memory corruption vulnerabilities in WebKit Process Model can be exploited to execute arbitrary code;
  3. Multiple memory corruption vulnerabilities in WebKit can be exploited to execute arbitrary code;
  4. A logic vulnerability in WebKit can be exploited to perform cross-site scripting attacks;
  5. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted text file to execute arbitrary code;
  6. A memory corruption vulnerability in Graphics Driver can be exploited to execute arbitrary code.
Affected products

Apple iCloud earlier than 7.15
Apple iCloud earlier than 11.0

Solution

Update to the latest version
Download iCloud

Original advisories

HT210728
HT210727

Impacts
?
ACE 
[?]

XSS/CSS 
[?]
Related products
Apple iCloud
CVE-IDS
?
CVE-2019-87500.0Unknown
CVE-2019-87100.0Unknown
CVE-2019-87660.0Unknown
CVE-2019-88150.0Unknown
CVE-2019-87820.0Unknown
CVE-2019-88220.0Unknown
CVE-2019-88230.0Unknown
CVE-2019-87830.0Unknown
CVE-2019-88110.0Unknown
CVE-2019-88130.0Unknown
CVE-2019-88140.0Unknown
CVE-2019-88190.0Unknown
CVE-2019-88160.0Unknown
CVE-2019-87840.0Unknown
CVE-2019-88200.0Unknown
CVE-2019-88210.0Unknown