CVE-2019-7287: Apple iOS Memory Corruption Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 4.6% chance of exploitation in the next 30 days.

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

Affected products

  • Apple iPhone OS: before 12.1.4 (fixed in 12.1.4)

Published 2019-12-18. Last modified 2026-06-17.