First published: Fri Nov 22 2019(Updated: )
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone 3GS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9536 is rated as high severity due to the potential for privilege escalation and arbitrary firmware installation with physical access.
To fix CVE-2019-9536, users should update their Apple iPhone 3GS to the latest firmware provided by Apple that addresses this vulnerability.
Only Apple iPhone 3GS devices are affected by CVE-2019-9536.
CVE-2019-9536 allows an attacker with physical access to install arbitrary firmware on the affected device.
Yes, exploiting CVE-2019-9536 requires physical access to the Apple iPhone 3GS.