CVE-2019-8641 is an out-of-bounds read vulnerability in Apple software. The issue was caused by insufficient input validation, allowing an attacker to read memory outside the intended bounds. This could potentially expose sensitive information or cause application instability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a working exploit for CVE-2019-8641, a remote code execution vulnerability in Apple's iMessage (affecting iOS and macOS). The exploit is structured as follows: - 'pwn.py' is the main orchestrator, handling the attack flow: it attaches to the 'imagent' process using Frida, injects a JavaScript hook ('hook.js') to intercept and modify iMessage payloads, and uses AppleScript ('sendMessage.applescript') to send crafted iMessages to the target Apple ID. - Payloads are generated using Python scripts (e.g., 'gen_payload_defer.py'), which create malicious NSKeyedArchiver-serialized objects and write them to '/private/var/tmp/com.apple.messages/payload'. - The Frida hook ('hook.js') intercepts message handling in the iMessage process, detects special trigger messages (e.g., 'INJECT_BP', 'INJECT_ATI'), and injects the malicious payload from the file into the message dictionary, causing the target to deserialize and execute the payload. - The exploit includes logic to bypass ASLR by probing the shared cache address space and uses shared cache profile files for this purpose. The main capability is remote code execution on the target device, demonstrated by opening the Calculator app. The exploit requires the attacker to have access to a macOS system with Frida and the ability to send iMessages. The repository is well-structured, with clear separation between payload generation, delivery, and exploitation logic. Several fingerprintable file paths are used for payload storage and delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.