Vulnerability Description
The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Ipados | < 13.3 |
| Apple | Iphone Os | < 13.3 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/HT210785Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210785Release NotesVendor Advisory
FAQ
What is CVE-2019-8857?
CVE-2019-8857 is a vulnerability with a CVSS score of 3.3 (LOW). The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if...
How severe is CVE-2019-8857?
CVE-2019-8857 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8857?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Ipados, Apple Iphone Os.