A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
Conclusion & alert: CVE-2019-7287 is rated Critical Active Threat (87.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.87%).Core evidence: CISA KEV confirms active exploitation (added 2022-05-23) affecting Apple / iOS. a weakness (CWE-787) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2019-7287
Name: Apple iOS Memory Corruption Vulnerability · CISA KEV detail
Exploit added: 2022-05-23
Action due: 2022-06-13
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2019-7287
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).