Vulnerabilities > CVE-2019-9536 - Improper Handling of Exceptional Conditions vulnerability in Apple Iphone 3GS

047910
CVSS 6.8 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
apple
CWE-755

Summary

Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.

Vulnerable Configurations

Part Description Count
Hardware
Apple
1