First published: Thu Feb 07 2019(Updated: )
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
Credit: an anonymous researcher Clement Lecigne Google Threat Analysis GroupIan Beer Google Project Zero Samuel Groß Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Multiple Products | ||
tvOS | <12.2 | 12.2 |
Apple iOS, iPadOS, and watchOS | <12.1.4 | 12.1.4 |
Apple iOS, iPadOS, and watchOS | <5.2 | 5.2 |
Apple macOS Mojave Supplemental Update | <10.14.3 | 10.14.3 |
iStyle @cosme iPhone OS | <12.1.4 | |
Apple iOS and macOS | <10.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-7286 is a memory corruption vulnerability in Apple Multiple Products that allows an application to gain elevated privileges.
CVE-2019-7286 affects iOS devices running up to version 12.1.4.
CVE-2019-7286 affects macOS devices running up to version 10.14.3.
To fix CVE-2019-7286 on iOS, update your device to iOS version 12.1.4 or later.
To fix CVE-2019-7286 on macOS, update your device to macOS version 10.14.3 or later.