SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Apple security updates October 2019

Apple security updates October 2019

Oct 10, 2019By Vidita V Koushik3 min read

Apple released a set of Apple security updates October 2019 for its products this month. There are a total of 24 CVEs which includes the first set of updates for Apple’s new macOS Catalina. Using a vulnerability scanning tool, we can detect these CVE’s.

MacOS Catalina, the latest version of Apple’s desktop operating system was released on October 7. Catalina comes with updated security features to protect the core operating system. MacOS runs in a read-only volume with Catalina, which prevents third-party applications from writing to sensitive parts of the system. With the coming of the new OS, Apple has also withdrawn support for 32-bit applications and the era of Apple iTunes has reached an end. A patch management solution can provide patches for the vulnerabilities.

6 out of 16 vulnerabilities in MacOS Catalina lead to Arbitrary Code Execution. Three vulnerabilities affecting Catalina are considered critical as they allow an attacker to execute arbitrary code with kernel privileges due to memory corruption issues in various components. Catalina was also affected by two browser related issues in the ‘Webkit’ component. While one bug exposed the user’s browsing history, the other bug did not delete the history with ‘Clear History and Website Data’.

Eight vulnerabilities were addressed in Apple iCloud. Six out of eight vulnerabilities lead to Arbitrary Code Execution. Two other vulnerabilities allow an attacker who processes maliciously crafted web content to conduct universal cross site scripting attacks. Also, Apple iTunes received 9 fixes with 7 CVEs addressing arbitrary code execution and 2 CVEs addressing cross site scripting vulnerabilities.

Apple Security Updates Summary :

Apple Security Updates October 2019 has addressed vulnerabilities in the following products:

  • Product : macOS Catalina 10.15
  • Affected OSmacOS
  • Affected features: AMD, CoreAudio, Crash Reporter, IOGraphics, Intel Graphics Driver, Kernel , Notes, PDFKit, SharedFileList, UIFoundation, WebKit, apache_mod_php, sips
  • Impact : Arbitrary Code Execution, Denial of Service, Information Disclosure
  • CVEs: CVE-2019-11041, CVE-2019-11042, CVE-2019-8701, CVE-2019-8705, CVE-2019-8717, CVE-2019-8730, CVE-2019-8745, CVE-2019-8748, CVE-2019-8755, CVE-2019-8757, CVE-2019-8758, CVE-2019-8768, CVE-2019-8769, CVE-2019-8770, CVE-2019-8772, CVE-2019-8781
  • Product : iCloud for Windows 10.7
  • Affected OS: Windows 10
  • Affected features: UIFoundation, WebKit
  • Impact : Arbitrary Code Execution, Universal Cross Site Scripting
  • CVEs: CVE-2019-8625, CVE-2019-8707, CVE-2019-8719, CVE-2019-8726, CVE-2019-8733, CVE-2019-8735, CVE-2019-8745, CVE-2019-8763
  • Product : iCloud for Windows 7.14
  • Affected OSWindows 7 
  • Affected features: UIFoundation, WebKit
  • Impact : Arbitrary Code Execution, Universal Cross Site Scripting
  • CVEs: CVE-2019-8625, CVE-2019-8707, CVE-2019-8719, CVE-2019-8726, CVE-2019-8733, CVE-2019-8735, CVE-2019-8745, CVE-2019-8763
  • Product : iTunes 12.10.1 for Windows
  • Affected OSWindows 7
  • Affected features: UIFoundation, WebKit
  • Impact : Arbitrary Code Execution, Universal Cross Site Scripting
  • CVEs: CVE-2019-8625, CVE-2019-8707, CVE-2019-8719, CVE-2019-8720, CVE-2019-8726, CVE-2019-8733, CVE-2019-8735, CVE-2019-8745, CVE-2019-8763

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Apple security updates October 2019 | SecPod