Junglewise Threat Intelligence

CVE-2019-7286: Apple Multiple Products Memory Corruption Vulnerability

CVE-2019-7286 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-23

Technologies: Apple watchOS, Apple Multiple Products, Apple Tvos. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple iOS, macOS, watchOS, and tvOS was caused by insufficient input validation. Successful exploitation allows an application to gain elevated privileges on the affected system.

Affected products

  • Apple iOS Before 12.1.4
  • Apple macOS Mojave Before 10.14.3 Supplemental Update
  • Apple watchOS Before 5.1.3
  • Apple tvOS Before 12.1.2

Timeline

  • 2019-12-18: disclosed: NVD Published Date
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2019-02-07: patched: Apple released security updates for iOS and macOS Mojave

Related threats