cbcvebase.
CVE-2019-7286
published 2019-12-18

CVE-2019-7286: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An…

PriorityP181high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-13
Exploited in the wild
EPSS
15.71%
96.5th percentile
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

Affected

8 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < iOS 12.1.4iOS 12.1.4
appleiphone_os< 12.1.412.1.4
applemac_os_x< 10.14.310.14.3
applemacos>= unspecified < macOS Mojave 10.14.3 Supplemental UpdatemacOS Mojave 10.14.3 Supplemental Update
applemacos_mojave_10.14.3_supplemental_update
appletvos
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

processcom.apple.cfprefsd.agent
processcom.apple.cfprefsd.daemon
commandCFPreferencesOperation=4 (free trigger)
commandCFPreferencesOperation=8 (heap spray fill)
commandCFPreferencesOperation=20 (use-after-free trigger loop)
commandCFPreferencesOperation=5 (outer message trigger)
  • Alert on cfprefsd spawning child processes or exhibiting privilege escalation (e.g., setuid/setgid calls) following receipt of malformed XPC messages — the exploit targets cfprefsd to gain elevated privileges.
  • This CVE is listed in CISA KEV as actively exploited in the wild; treat any unpatched iOS < 12.1.4 or macOS < 10.14.3 Supplemental Update device as high-priority for incident investigation.
  • ·The fake_cache_bucket.cached_sel address is computed at runtime as 0x7fff00000000 + NSSelectorFromString(@"dealloc"), making the exact selector address variable across runs and OS versions; static byte signatures for this field will not be reliable.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.