ZeroHour

CVE-2019-8900

mass

Unauthenticated Local Boot-Time Code Execution in Apple SecureROM (checkm8)

CVSS 3.1
6.8 medium
EPSS
69%p99
Published
()
Modified
AI analysis

A flaw in the SecureROM (BootROM) of certain Apple devices allows an unauthenticated local attacker to execute arbitrary code when the device boots. Triggering it requires physical access: the attacker must connect the device to a computer and place it in Device Firmware Update (DFU) mode during boot. An attacker gains the ability to run code on the device during that boot session, but the exploit is not persistent — a reboot reverts any software changes — and without the device's unlock PIN or fingerprint the attacker cannot reach data protected by Secure Enclave or Touch ID. Affected are Apple devices with a vulnerable SecureROM; per the source data no specific model list or version range is given, and because BootROM is read-only, vulnerable devices cannot be fully patched by firmware updates. Per available dashboard data there is no known in-the-wild exploitation and no public PoC (not in CISA KEV), although EPSS assigns a 68.8% probability of exploitation within 30 days (99th percentile).

What to do: No firmware update can remediate an immutable BootROM flaw, so treat this as a physical-security issue: avoid leaving devices unattended, and only put devices into DFU mode connected to trusted, up-to-date computers. If untrusted access is suspected, simply rebooting the device clears any non-persistent changes made during the exploited boot session. Keep host computers used for device restores and DFU work patched, and protect unlock credentials, since the PIN/fingerprint gates access to Secure Enclave-protected data.

Affected
Apple SecureROM (BootROM) of affected Apple devices
Estimated exposure
mass≈100s of millions of devices potentially affected (cumulative installed base of vulnerable Apple iPhone/iPad-class devices), though exploitation requires… — The flaw resides in the immutable BootROM shipped across Apple's high-volume device families over many years, so the plausible affected population is on the order of hundreds of millions of devices based on cumulative Apple hardware sales,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.

Vendors
apple
Products
securerom
Weakness
CWE-94
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.