A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
Conclusion & alert: CVE-2019-8526 is rated Active Exploitation (71.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%).Core evidence: CISA KEV confirms active exploitation (added 2023-04-17) affecting Apple / macOS. a weakness (CWE-416) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2019-8526
Name: Apple macOS Use-After-Free Vulnerability · CISA KEV detail
Exploit added: 2023-04-17
Action due: 2023-05-08
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2019-8526
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).