CVE-2019-8900General(apple / a10_fusion)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the device: the device must be plugged in to a computer upon booting, and it must be put into Device Firmware Update (DFU) mode. The exploit is not persistent; rebooting the device overrides any changes to the device's software that were made during an exploited session on the device. Additionally, unless an attacker has access to the device's unlock PIN or fingerprint, an attacker cannot gain access to information protected by Apple's Secure Enclave or Touch ID features.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a10_fusion
  • a10x_fusion
  • a11_bionic
  • a5

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
a10_fusiona10x_fusiona11_bionica5a5xa6a6xa7a8a8x

1 version affected across 13 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 1Technical Details · 2026-05-11: 105-11
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Eng.Ebrahim@Mrtakla0x
    General

    عندي ايياد قديم وناسي الايكلاود حقه وحاولت افرمته لكن مااقدر ، قريت عن ثغره Checkm8 -CVE-2019-8900 الفكره هي ان نجبر ال OS مايتعرف على الجهاز انه مطفي ومسكر ال exploit يسوي inject للباث الاساسي ل Lockdown واذا سواها وتمت راح يفتح لك الشاشه الرئيسيه على طول عموماً بجرب بكرا

    Post summary

    The user references CVE-2019-8900 in an attempt to exploit an iPhone, describing a conceptual injection strategy, but provides no PoC or exploit code, nor evidence of active attacks or patches.

    0001191
    76 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
HWapplea10_fusion---
HWapplea10x_fusion---
HWapplea11_bionic---
HWapplea5---
HWapplea5x---
HWapplea6---
HWapplea6x---
HWapplea7---
HWapplea8---
HWapplea8x---
HWapplea9---
HWapplea9x---
OSapplesecurerom---

Explore more