Vulnerability record · CVE-2019-7286 · published 18 December 2019
CVE-2019-7286: Apple iOS and macOS memory corruption allows privilege escalation
Apple · Iphone Os
CVE-2019-7286 is an out-of-bounds write (CWE-787) in Apple iOS and macOS that was fixed through improved input validation in iOS 12.1.4 and macOS Mojave 10.14.3 Supplemental Update. The flaw lets an application gain elevated privileges, making it a local privilege escalation risk on affected Apple devices.
Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with known exploitation and a high CVSS score, but it requires local access and user interaction, limiting broad remote exploitation.
What it is
CVE-2019-7286 is an out-of-bounds write (CWE-787) in Apple iOS and macOS that was fixed through improved input validation in iOS 12.1.4 and macOS Mojave 10.14.3 Supplemental Update. The flaw lets an application gain elevated privileges, making it a local privilege escalation risk on affected Apple devices.
Impact
An attacker who can run code on the target gains elevated privileges, potentially enabling further compromise of the device. The CVSS 3.1 base score is 7.8 (HIGH) with high confidentiality, integrity, and availability impact.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the flaw is reached by a local application and needs a user to trigger it. No remote or network vector is indicated.
Exploitation
CVE-2019-7286 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.15582 (96.651 percentile), and references are vendor advisories plus the CISA KEV entry.
What to do
- Apply the vendor updates: iOS 12.1.4 and macOS Mojave 10.14.3 Supplemental Update, or later supported versions.
- Follow CISA KEV required action to apply updates per vendor instructions by the due date.
- Restrict installation and execution of untrusted applications on managed Apple devices.
- Keep macOS and iOS devices on currently supported releases to receive ongoing security fixes.
- Monitor Apple security advisories for related fixes and re-check affected versions.
Detection
- Monitor for unexpected privilege escalation or anomalous process behavior on Apple endpoints.
- Track application crashes or memory corruption indicators that may precede exploitation.
- Use endpoint detection to flag untrusted applications attempting to gain elevated privileges.
- Audit device patch levels against iOS 12.1.4 and macOS Mojave 10.14.3 Supplemental Update baselines.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7286 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT209520 | Vendor Advisory |
| https://support.apple.com/HT209521 | Vendor Advisory |
| https://support.apple.com/HT209601 | Vendor Advisory |
| https://support.apple.com/HT209602 | Vendor Advisory |
| https://support.apple.com/HT209520 | Vendor Advisory |
| https://support.apple.com/HT209521 | Vendor Advisory |
| https://support.apple.com/HT209601 | Vendor Advisory |
| https://support.apple.com/HT209602 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7286 | US Government Resource |
Track CVE-2019-7286 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7286), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.