CVE-2019-9536, known as 'alloc8', is a bootrom vulnerability affecting the Apple iPhone 3GS. It stems from a flawed memory allocation implementation that returns a non-NULL pointer even when memory allocation fails. This vulnerability has a CVSS score of 6.8 (Medium) and requires physical access to the device (AV:P), allowing an attacker to install arbitrary firmware, leading to high impact on confidentiality, integrity, and availability. Despite its potential for complete device compromise, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:apple:iphone_3gs:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.