CVE-2019-14899 - Apple Mac OS, Openbsd OpenBSD and Linux Linux Kernel

Critical 7.4

A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.

Affected software

Apple Mac OS

Openbsd OpenBSD

Linux Linux Kernel

Freebsd Freebsd

Apple iPhone OS

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.