CVE-2019-7286 is a memory corruption vulnerability in iOS and macOS that could allow an application to gain elevated privileges due to insufficient input validation. This high-severity flaw (CVSS 7.8) has a low attack complexity, requiring user interaction, and could lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with public exploit code available (EDB-46803), and has garnered significant community and media attention, including reports of its use in data-stealing malware attacks. Apple addressed this issue in iOS 12.1.4 and macOS Mojave 10.14.3 Supplemental Update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.14.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.