Vulnerability record · CVE-2019-8526 · published 18 December 2019
CVE-2019-8526: Apple macOS use-after-free allows privilege escalation
Apple · Mac Os X
CVE-2019-8526 is a use-after-free (CWE-416) in Apple macOS, fixed in macOS Mojave 10.14.4 via improved memory management. Successful exploitation lets a local application gain elevated privileges, making it a privilege-escalation flaw on affected systems.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS of 7.8, though it requires local access and low privileges.
What it is
CVE-2019-8526 is a use-after-free (CWE-416) in Apple macOS, fixed in macOS Mojave 10.14.4 via improved memory management. Successful exploitation lets a local application gain elevated privileges, making it a privilege-escalation flaw on affected systems.
Impact
An attacker who can run code on the host gains elevated privileges, potentially reaching root-level access. That enables further compromise of the machine and its data.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so it is reached by a locally running application rather than over the network. No remote or unauthenticated path is described.
Exploitation
CISA added it to the KEV catalog on 2023-04-17, indicating known exploitation in the wild; EPSS is low (0.00701, ~51.5th percentile), and no ransomware campaign use is recorded.
What to do
- Update macOS to Mojave 10.14.4 or later per Apple's advisory (HT209600).
- Prioritize patching hosts still running pre-10.14.4 macOS, given KEV status.
- Restrict execution of untrusted local applications and limit standard user privileges.
- Monitor for and remove unapproved software that could trigger the use-after-free locally.
- Track KEV remediation deadlines (due 2023-05-08) for any remaining unpatched systems.
Detection
- Audit macOS versions across the fleet and flag any host below 10.14.4.
- Monitor for unexpected privilege escalation or processes gaining root unexpectedly.
- Review application execution and crash logs for use-after-free style memory faults.
- Alert on execution of untrusted or newly introduced local binaries on macOS endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-8526 to the Known Exploited Vulnerabilities catalog on 17 April 2023 as "Apple macOS Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 May 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT209600 | Release NotesVendor Advisory |
| https://support.apple.com/HT209600 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8526 | US Government Resource |
Track CVE-2019-8526 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-8526), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.