nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-7286 CVE-2019-7286
HIGHCISA KEV
Apple Multiple Products Memory Corruption Vulnerability
Record summary
CVE-2019-7286 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2019-7286 in KEV.
Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 23, 2022 · CISA
- VulnCheck KEV
- Listed · Feb 7, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
| CVE List | Before iOS 12.1.4 | affected | |
macOSBrowse Apple / macOS | CVE List | Before macOS Mojave 10.14.3 Supplemental Update | affected |
Proofs of concept
1Catalogued exploits
ExploitDBiOS 12.1.3 - 'cfprefsd' Memory CorruptionExploitDB exploitby ZecOpsNot analyzed1 file
References
6support.apple.com
https://support.apple.com/HT209520 support.apple.com
https://support.apple.com/HT209521 support.apple.com
https://support.apple.com/HT209601 support.apple.com
https://support.apple.com/HT209602 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7286