← Vulnerability feed

Vulnerability record · CVE-2019-8900 · published 21 February 2025

CVE-2019-8900: Apple SecureROM boot code injection via physical DFU access

Apple · Securerom

Apple SecureROM contains a code injection flaw that lets an unauthenticated local attacker run arbitrary code when a device boots. The attacker needs physical access, the device plugged into a computer, and entry into DFU mode. Because the change is not persistent, a reboot clears the exploited session, limiting lasting compromise.

6.8 CVSS 3.1 Medium EPSS 69% · top 0.7% CWE-94 · Code injection
6.8CVSS 3.1 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityPhysical access is required and the exploit is non-persistent, but arbitrary boot code execution and a very high EPSS score keep it relevant for devices exposed to untrusted physical handling.

What it is

Apple SecureROM contains a code injection flaw that lets an unauthenticated local attacker run arbitrary code when a device boots. The attacker needs physical access, the device plugged into a computer, and entry into DFU mode. Because the change is not persistent, a reboot clears the exploited session, limiting lasting compromise.

Impact

An attacker with physical access gains arbitrary code execution at boot on the affected device. Data protected by the Secure Enclave or Touch ID remains inaccessible without the unlock PIN or fingerprint.

Attack surface

Reached only through physical access: the device must be connected to a computer and placed in DFU mode at boot. No authentication or user interaction is required beyond that physical setup, per the CVSS vector AV:P/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record. EPSS is high (0.68782, 99.31st percentile), suggesting elevated predicted exploitation activity, but the record provides no confirmed in-the-wild evidence.

What to do

  • Apply Apple's SecureROM/boot firmware fixes for affected devices as soon as they are available.
  • Restrict physical access to devices and keep them under supervision to prevent DFU-mode attacks.
  • Enforce strong device unlock PINs and biometrics so Secure Enclave and Touch ID data stay protected even if boot code is exploited.
  • Monitor for unexpected reboots or boot anomalies on high-value devices and treat unexplained DFU activity as suspicious.
  • Maintain an inventory of affected Apple models and prioritize patching based on exposure to untrusted physical handling.

Detection

  • Audit device management logs for DFU-mode entries or boot events outside normal maintenance windows.
  • Correlate physical access records with device boot timestamps to flag unexplained DFU sessions.
  • Monitor for post-boot behavioral anomalies on devices that were recently connected to unknown computers.
  • Track Apple security advisories for SecureROM fixes and verify firmware versions across the fleet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.kb.cert.org/vuls/id/941987 Third Party Advisory

Track CVE-2019-8900 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2019-8900), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.