Vulnerability record · CVE-2019-7287 · published 18 December 2019
CVE-2019-7287: Apple iOS memory corruption allows kernel code execution
Apple · Iphone Os
CVE-2019-7287 is an out-of-bounds write (CWE-787) in Apple iOS that was fixed in iOS 12.1.4 through improved input validation. A memory corruption flaw in the kernel means a malicious application can potentially run code with kernel privileges, which is the highest level of access on the device.
Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and grants kernel-level code execution, though it requires local access and user interaction.
What it is
CVE-2019-7287 is an out-of-bounds write (CWE-787) in Apple iOS that was fixed in iOS 12.1.4 through improved input validation. A memory corruption flaw in the kernel means a malicious application can potentially run code with kernel privileges, which is the highest level of access on the device.
Impact
An attacker who can get a crafted application onto the device gains arbitrary code execution at kernel privilege, effectively full control of the operating system. That can lead to persistent compromise, data theft, or disabling of security controls.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker must already have code running on the device or convince the user to open or install something. It is not remotely reachable over the network without that local foothold.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-23, indicating exploitation in the wild; EPSS gives a 30-day probability of 0.04551 (91st percentile). No ransomware campaign use is documented.
What to do
- Update iOS to 12.1.4 or later immediately; this is the vendor fix and the required KEV action.
- Enforce a minimum iOS version through MDM or device policy so unpatched devices are blocked or flagged.
- Restrict installation of applications to trusted sources and review enterprise-signed apps, since the attack requires local code execution.
- Monitor for and remove suspicious or sideloaded applications on managed devices.
Detection
- Inventory iOS versions across managed and BYOD devices and alert on any device below 12.1.4.
- Monitor for unexpected kernel panics or crashes that could indicate memory corruption exploitation attempts.
- Review application installation logs for sideloaded or enterprise-signed apps that bypass the App Store.
- Correlate CISA KEV status with asset inventory to confirm no exposed devices remain unpatched.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7287 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Apple iOS Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT209520 | Release NotesVendor Advisory |
| https://support.apple.com/HT209520 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7287 | US Government Resource |
Track CVE-2019-7287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7287), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.