Three out of the four flaws fixed with iOS 12.1.4 were exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7286 | Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited. Do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program. | 7.8 | 16% | KEV |
| masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown | |
| CVE-2019-7287 | Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown. Do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release. | 7.8 | 5% | KEV |
| mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019) |
Full article311 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 08, 2019

Security experts at Google discovered that two of the zero-day vulnerabilities patched by Apple with the release of iOS 12.1.4 were exploited in the wild.
Security researchers at Google revealed that two of the zero-day flaws addressed by Apple with the release of iOS 12.1.4 were exploited in the wild.
Apple iOS 12.1.4 version addresses four vulnerabilities, two issues associated with the FaceTime bug and two memory corruption flaws that could be exploited by attackers to elevate privileges and execute arbitrary code.
The CVE-2019-7287 vulnerability affects the IOKit and it can be exploited by a malicious app to execute arbitrary code with kernel privileges.
“An application may be able to execute arbitrary code with kernel privileges.” reads the security advisory.
“A memory corruption issue was addressed with improved input validation.”
The CVE-2019-7286 vulnerability impacts the Foundation component in iOS, it could allow a malicious application to gain elevated privileges.
“An application may be able to gain elevated privileges” continues the advisory. “A memory corruption issue was addressed with improved input validation.”
The flaws were discovered by Clement Lecigne of Google Threat Analysis Group, and Ian Beer and Samuel Groß of Google Project Zero. Apple also credited an anonymous researcher for the discovery of the vulnerabilities.
Project Zero Team Lead Ben Hawkes revealed that both CVE-2019-7286 and CVE-2019-7287 have been exploited in the wild. Google experts did not reveal technical details on the attacks they observed in the wild.
The popular Google Project white hat hacker Tavis Ormandy confirmed that three of the four vulnerabilities addressed by Apple were exploited by attackers in the wild.
Three out of the four vulnerabilities in the latest iOS advisory were exploited in the wild, yikes.
— Tavis Ormandy (@taviso) February 7, 2019
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, iOS 12.1.4)
[adrotate banner=”5″] [adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/80823/hacking/ios-12-1-4-flaws.html