This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | - | 10.14.6 |
| apple / tvos | - | 12.4 |
| apple / watchos | - | 5.3 |
| apple / iphone_os | - | 12.4 |