Vulnerability record · CVE-2019-8900 · published 21 February 2025
CVE-2019-8900: Apple SecureROM boot code injection via physical DFU access
Apple · Securerom
Apple SecureROM contains a code injection flaw that lets an unauthenticated local attacker run arbitrary code when a device boots. The attacker needs physical access, the device plugged into a computer, and entry into DFU mode. Because the change is not persistent, a reboot clears the exploited session, limiting lasting compromise.
Description
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
medium priorityPhysical access is required and the exploit is non-persistent, but arbitrary boot code execution and a very high EPSS score keep it relevant for devices exposed to untrusted physical handling.
What it is
Apple SecureROM contains a code injection flaw that lets an unauthenticated local attacker run arbitrary code when a device boots. The attacker needs physical access, the device plugged into a computer, and entry into DFU mode. Because the change is not persistent, a reboot clears the exploited session, limiting lasting compromise.
Impact
An attacker with physical access gains arbitrary code execution at boot on the affected device. Data protected by the Secure Enclave or Touch ID remains inaccessible without the unlock PIN or fingerprint.
Attack surface
Reached only through physical access: the device must be connected to a computer and placed in DFU mode at boot. No authentication or user interaction is required beyond that physical setup, per the CVSS vector AV:P/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record. EPSS is high (0.68782, 99.31st percentile), suggesting elevated predicted exploitation activity, but the record provides no confirmed in-the-wild evidence.
What to do
- Apply Apple's SecureROM/boot firmware fixes for affected devices as soon as they are available.
- Restrict physical access to devices and keep them under supervision to prevent DFU-mode attacks.
- Enforce strong device unlock PINs and biometrics so Secure Enclave and Touch ID data stay protected even if boot code is exploited.
- Monitor for unexpected reboots or boot anomalies on high-value devices and treat unexplained DFU activity as suspicious.
- Maintain an inventory of affected Apple models and prioritize patching based on exposure to untrusted physical handling.
Detection
- Audit device management logs for DFU-mode entries or boot events outside normal maintenance windows.
- Correlate physical access records with device boot timestamps to flag unexplained DFU sessions.
- Monitor for post-boot behavioral anomalies on devices that were recently connected to unknown computers.
- Track Apple security advisories for SecureROM fixes and verify firmware versions across the fleet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.kb.cert.org/vuls/id/941987 | Third Party Advisory |
Track CVE-2019-8900 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-8900), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.