VDB
GCVE-110-CERTCC-2019-941987
GCVE-110-CERTCC-2019-941987
Advisory PublishedCVSS 5.6/10
### Overview
Some Apple devices are vulnerable to arbitrary code execution at the Boot ROM level (called "SecureROM" by Apple) by exploiting a use-after-free vulnerability. Successful exploitation results in the ability to execute arbitrary code on the device. <a href="https://github.com/axi0mX/ipwndfu/blob/master/checkm8.py">checkm8</a> is a public exploit for this vulnerability.
### Description
<a href="https://github.com/axi0mX/ipwndfu">A vulnerability in the SecureROM</a> of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. SecureROM, which is located within the processor, contains the first code executed by the processor upon booting the device. Because SecureROM is read-only, it cannot be patched with a firmware update.
Apple devices that implement processing chips A5 through A11 are vulnerable. This corresponds to iPhone models 4S through X; additionally, certain models of iPad, Apple Watch, iPod Touch, and Apple TV are vulnerable. See the <a href="https://blog.malwarebytes.com/mac/2019/09/new-ios-exploit-checkm8-allows-permanent-compromise-of-iphones/">Malwarebytes blog entry</a> for a full list of affected devices. Further details about the vulnerability are available in <a href="https://arstechnica.com/information-technology/2019/09/developer-of-checkm8-explains-why-idevice-jailbreak-exploit-is-a-game-changer/">Ars Technica's interview with the vulnerability's discoverer</a>.
### Impact
This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.
### Solution ###
The CERT/CC is currently unaware of a practical solution to this problem. Because the vulnerability exists in the read-only Boot ROM level, replacing the device with one that does not contain a vulnerable processing chip is the only solution that guarantees immunity to the vulnerability.
Generally speaking, [physical access](https://www.kb.cert.org/vuls/id/789985) to a computer system can be used to bypass software-based access control mechanisms.
### Acknowledgements
axi0mX developed the checkm8 exploit for this vulnerability.
This document was written by Eric Hatleback, Will Dormann, and Art Manion.
Risk Scores
CVSS 2.0
5.6/10
Medium · AV:L/AC:L/Au:N/C:P/I:C/A:N
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_direct_report0
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score5.3remediation_levelUreport_confidenceCenvironmental_score6.79201114368target_distributionHenvironmental_vectorCDP:ND/TD:H/CR:ND/IR:H/AR:ND
Aliases
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.