Record summary

CVE-2019-7286 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2019-7286 in KEV.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · May 23, 2022 · CISA
VulnCheck KEV
Listed · Feb 7, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore iOS 12.1.4affected
CVE ListBefore macOS Mojave 10.14.3 Supplemental Updateaffected

Proofs of concept

1

Catalogued exploits

ExploitDBiOS 12.1.3 - 'cfprefsd' Memory CorruptionExploitDB exploitby ZecOpsNot analyzed1 file
ExploitDB

PoC details

References

6