New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 8.9
Synopsis
The version of Apple iOS running on the mobile device is affected by multiple vulnerabilities.
Description
The version of Apple iOS running on the mobile device is prior to 12.1.3. It is, therefore, affected by multiple vulnerabilities:
- Multiple unspecified vulnerabilities in WebKit can lead to arbitrary code execution if a user is enticed to visit a malicious web page.
(CVE-2019-6227, CVE-2019-6233, CVE-2019-6234)
- A maliciously crafted SQL query could lead to arbitrary code execution.
(CVE-2018-20346, CVE-2018-20505, CVE-2018-20506)
- A malicious application could lead to arbitrary code execution with kernel privileges.
(CVE-2019-6218)
Additionally several other vulnerabilities exist, the highest of which could allow an attacker to perform a remote code execution attack by enticing a user to view malicious web content.
Solution
Upgrade to Apple iOS version 12.1.3 or later.