CVE-2019-8900

MEDIUM
Published Feb 21, 2025 Modified Jul 29, 2025 CWE-94

Description

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.

Is your site exposed to CVE-2019-8900?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-94 CWE-94

Affected Products

Vendor Product
apple securerom
apple a10_fusion
apple a10x_fusion
apple a11_bionic
apple a5
apple a5x
apple a6
apple a6x
apple a7
apple a8
apple a8x
apple a9
apple a9x

References

Frequently Asked Questions

What is CVE-2019-8900? +
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features. It has a CVSS v3.1 base score of 6.8 (MEDIUM).
How severe is CVE-2019-8900? +
CVE-2019-8900 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2019-8900? +
CVE-2019-8900 affects products from apple, specifically: a10_fusion, a10x_fusion, a11_bionic, a5, a5x, a6, a6x, a7, a8, a8x, a9, a9x, securerom. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2019-8900? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2019-8900 — free, no signup required.