CVE-2019-8606
Description
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.5. A local user may be able to load unsigned kernel extensions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
macOS Mojave 10.14.5 fixes a symlink validation issue that could let a local user load unsigned kernel extensions.
Vulnerability
A validation issue existed in the handling of symlinks in macOS prior to version 10.14.5. This allowed a local user to bypass the normal security checks for loading kernel extensions. The affected versions are macOS Mojave 10.14.4 and earlier, macOS High Sierra 10.13.6, and macOS Sierra 10.12.6 [1]. The issue is addressed in macOS Mojave 10.14.5 by improving the validation of symlinks [1].
Exploitation
An attacker needs local user access to the system. By crafting a malicious symlink that points to an unsigned kernel extension, the attacker can trick the system into loading it. No additional authentication or user interaction beyond having a local account is required.
Impact
A successful exploit allows a local user to load unsigned kernel extensions, which can lead to arbitrary code execution with kernel-level privileges, potentially resulting in full compromise of the system.
Mitigation
Apple released macOS Mojave 10.14.5 on May 13, 2019, which fixes this issue [1]. Users should update to the latest version of macOS. There is no evidence of this CVE being listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.14.5
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- support.apple.com/HT210119mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.