CVE-2019-6238
Description
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted package may lead to arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A symlink validation issue in the macOS Installer package processing could let a malicious package execute arbitrary code.
Vulnerability
The vulnerability is a validation issue in how macOS handles symlinks during the processing of installer packages. This flaw existed in the Installer component, which processes .pkg files. When a package contains a malicious symlink, the validation check was insufficient, allowing the symlink to point to an unintended location. The issue affects macOS Mojave 10.14.3 and earlier, macOS High Sierra, and macOS Sierra. It is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, and Security Update 2019-002 Sierra [1].
Exploitation
An attacker would need to craft a maliciously constructed package (.pkg) that contains a symlink with a specially crafted path. The package must then be processed by the Installer application. No special privileges or prior access to the target system are required to trigger the vulnerability, but the user must open the malicious package. The attacker could deliver the package via a website, email attachment, or other means [1].
Impact
Successful exploitation could lead to arbitrary code execution on the affected system. By exploiting the symlink validation flaw, an attacker could write files to arbitrary locations, potentially leading to privilege escalation or arbitrary code execution with the privileges of the user processing the package. The exact level of compromise depends on the content placed at the target location [1].
Mitigation
Apple released fixes in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, and Security Update 2019-002 Sierra on March 25, 2019 [1]. Users should update to these versions or later. No workarounds are documented. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog (as of this writing).
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <10.14.4
<10.14.4+ 1 more
- (no CPE)range: <10.14.4
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- support.apple.com/en-us/HT209600mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.