LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7286: Apple Multiple Products Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7286 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.

CVE-2019-7286 is a memory corruption vulnerability affecting multiple Apple products, including iOS, macOS, watchOS, and tvOS. It can allow an attacker to escalate privileges on a compromised device. For IT and security teams managing Apple fleets, this matters because successful privilege escalation can turn limited access into full control of the system, enabling further persistence, data access, or lateral movement. Specifics such as exact affected builds must be confirmed against the vendor advisory.

CISA notes the issue as a memory corruption flaw that could allow privilege escalation and directs organizations to apply updates per vendor instructions. Known ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-787 (out-of-bounds write), a form of memory corruption. In this class of flaw, software writes data past the bounds of an allocated buffer or memory region. That corruption can overwrite adjacent structures, function pointers, or control data.

An attacker who can trigger the vulnerable code path may cause the process to behave unexpectedly. On Apple platforms this can be leveraged to escalate privileges—moving from a lower-privileged context to a higher one. Public detail on the precise trigger, required user interaction, or exact exploitation steps is limited; defenders should treat it as a privilege-escalation risk within the memory-corruption class and rely on the vendor advisory for technical depth rather than assuming unstated mechanics.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS, macOS, watchOS, and tvOS. These operating systems commonly run on iPhones, iPads, Macs, Apple Watches, and Apple TVs in both corporate and BYOD environments.

How to remediate

Patching is the primary remediation. Apply the updates Apple released for the affected products, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is not possible, reduce exposure with compensating controls while you schedule the update.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to broader compromise and data exposure. If you suspect devices were targeted before patching, examine them for persistence, review access logs for sensitive resources, and follow your incident-response process. You can also run a free exposure scan of your email addresses to check whether credentials or personal data appear in known breach datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-787
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities