CVE-2019-7286
HIGH KEViPhone OS < 12.1.4 and macOS < 10.14.3 - Out-of-bounds Write
Title source: llmExploitation Summary
CVE-2019-7286 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 23, 2022. EIP tracks 1 public exploit from researchers including ZecOps.
AI-analyzed exploit summary This exploit targets CVE-2019-7286, a heap overflow vulnerability in Apple's cfprefsd. It uses heap spraying and XPC message manipulation to achieve arbitrary code execution by corrupting Objective-C object structures.
Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
Exploits (1)
This exploit targets CVE-2019-7286, a heap overflow vulnerability in Apple's cfprefsd. It uses heap spraying and XPC message manipulation to achieve arbitrary code execution by corrupting Objective-C object structures.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H