ZeroHour

CVE-2019-7287

KEVmass

Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution

CISA: Apple iOS Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p91
Published
()
KEV added
AI analysis

Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown.

What to do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release.

Affected
Apple iPhone OS (iOS)iOS versions prior to 12.1.4 (i.e., 12.1.3 and earlier at time of disclosure; fixed in iOS 12.1.4)
Estimated exposure
mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019) — Estimate derived from Apple's active iPhone installed base (roughly 1.4 billion devices in early 2019) combined with iOS 12's ~80% adoption share among active iPhones at the time, implying several hundred million devices on unpatched iOS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

CISA Known Exploited Vulnerability
Affected
Apple iOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news