CVE-2019-8900
massUnauthenticated Local Boot-Time Code Execution in Apple SecureROM (checkm8)
A flaw in the SecureROM (BootROM) of certain Apple devices allows an unauthenticated local attacker to execute arbitrary code when the device boots. Triggering it requires physical access: the attacker must connect the device to a computer and place it in Device Firmware Update (DFU) mode during boot. An attacker gains the ability to run code on the device during that boot session, but the exploit is not persistent — a reboot reverts any software changes — and without the device's unlock PIN or fingerprint the attacker cannot reach data protected by Secure Enclave or Touch ID. Affected are Apple devices with a vulnerable SecureROM; per the source data no specific model list or version range is given, and because BootROM is read-only, vulnerable devices cannot be fully patched by firmware updates. Per available dashboard data there is no known in-the-wild exploitation and no public PoC (not in CISA KEV), although EPSS assigns a 68.8% probability of exploitation within 30 days (99th percentile).
What to do: No firmware update can remediate an immutable BootROM flaw, so treat this as a physical-security issue: avoid leaving devices unattended, and only put devices into DFU mode connected to trusted, up-to-date computers. If untrusted access is suspected, simply rebooting the device clears any non-persistent changes made during the exploited boot session. Keep host computers used for device restores and DFU work patched, and protect unlock credentials, since the PIN/fingerprint gates access to Secure Enclave-protected data.
| Apple SecureROM (BootROM) of affected Apple devices | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.
- Vendors
- apple
- Products
- securerom
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.