ZeroHour

CVE-2019-7286

KEVmass

Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited.

What to do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program.

Affected
Apple iPhone OS (iOS)All versions prior to iOS 12.1.4
Apple macOS (Mac OS X) - MojavemacOS Mojave prior to the 10.14.3 Supplemental Update
Estimated exposure
masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown — Apple reported roughly 1.4 billion active devices in early 2019 and every iOS device below 12.1.4 and macOS Mojave system lacking the 10.14.3 Supplemental Update was exposed at disclosure, implying an affected population on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os, mac os x
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news