← Vulnerability feed

Vulnerability record · CVE-2019-8526 · published 18 December 2019

CVE-2019-8526: Apple macOS use-after-free allows privilege escalation

Apple · Mac Os X

CVE-2019-8526 is a use-after-free (CWE-416) in Apple macOS, fixed in macOS Mojave 10.14.4 via improved memory management. Successful exploitation lets a local application gain elevated privileges, making it a privilege-escalation flaw on affected systems.

7.8 CVSS 3.1 High CISA KEV since 17 Apr 2023 EPSS 0.70% · top 48.7% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 7.2
0.70%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS of 7.8, though it requires local access and low privileges.

What it is

CVE-2019-8526 is a use-after-free (CWE-416) in Apple macOS, fixed in macOS Mojave 10.14.4 via improved memory management. Successful exploitation lets a local application gain elevated privileges, making it a privilege-escalation flaw on affected systems.

Impact

An attacker who can run code on the host gains elevated privileges, potentially reaching root-level access. That enables further compromise of the machine and its data.

Attack surface

The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so it is reached by a locally running application rather than over the network. No remote or unauthenticated path is described.

Exploitation

CISA added it to the KEV catalog on 2023-04-17, indicating known exploitation in the wild; EPSS is low (0.00701, ~51.5th percentile), and no ransomware campaign use is recorded.

What to do

  • Update macOS to Mojave 10.14.4 or later per Apple's advisory (HT209600).
  • Prioritize patching hosts still running pre-10.14.4 macOS, given KEV status.
  • Restrict execution of untrusted local applications and limit standard user privileges.
  • Monitor for and remove unapproved software that could trigger the use-after-free locally.
  • Track KEV remediation deadlines (due 2023-05-08) for any remaining unpatched systems.

Detection

  • Audit macOS versions across the fleet and flag any host below 10.14.4.
  • Monitor for unexpected privilege escalation or processes gaining root unexpectedly.
  • Review application execution and crash logs for use-after-free style memory faults.
  • Alert on execution of untrusted or newly introduced local binaries on macOS endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-8526 to the Known Exploited Vulnerabilities catalog on 17 April 2023 as "Apple macOS Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 May 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8526 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed8.8CVE-2021-1789Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Process…KEVEPSS 14%analysed7.8CVE-2021-30713Apple macOS privacy preference bypass via missing authorizationmacOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferen…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2019-8526), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.