libxpc on MacOS version 10.14.1 suffers from an arbitrary mach port name deallocation in XPC services due to invalid mach message parsing in _xpc_serializer_unpack.
861787c4c8e28e6258f60f01561930d07585075db06c25a1f80b7aadb5eeb770
Apple Security Advisory 2019-1-22-2 - macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra are now available and addresses buffer overflow, code execution, and denial of service vulnerabilities.
07dfb353b9339db985c408e32871a075cb57f6f7bfc5edd7f63917f471a9b513
Apple Security Advisory 2019-1-22-4 - tvOS 12.1.2 is now available and addresses buffer overflow, code execution, and cross site scripting vulnerabilities.
e0c71ee19c824e7d6de77e42924d5b3e248bbbde354d1b3ed01c90111c895d8b
Apple Security Advisory 2019-1-22-1 - iOS 12.1.3 is now available and addresses buffer overflow, code execution, cross site scripting, and denial of service vulnerabilities.
b0b91011b4fcb4c74afc071b7c0d0533b15c5c94660e562202e08ce47ea91216