Check Point Research disclosed that a crafted SQLite database can be weaponized to achieve code execution by exploiting memory-corruption flaws in the SQLite engine itself, even when an application only performs hardcoded queries against untrusted data. The researchers described two techniques—Query Hijacking and Query Oriented Programming (QOP)—that abuse schema elements such as VIEWs and virtual-table features to redirect execution into attacker-controlled paths without requiring a surrounding scripting environment.
The report demonstrated the approach in two practical scenarios: remote code execution against a PHP7-based password-stealer backend and privileged persistence on iOS by replacing a frequently queried SQLite database. The research also pointed to risky virtual-table modules including FTS and RTREE, referenced earlier issues such as CVE-2015-7036 and CVE-2019-8457, and said Apple assigned CVE-2019-8600, CVE-2019-8598, CVE-2019-8602, and CVE-2019-8577 after responsible disclosure.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published findings showing that a malicious SQLite database can achieve code execution through memory-corruption bugs using SQL-language features alone. The work introduced Query Hijacking and Query Oriented Programming (QOP) and demonstrated remote code execution against a PHP7 password-stealer backend as well as iOS persistence via a malicious contacts database.
Following responsible disclosure of the iOS-related findings, Apple assigned CVE-2019-8600, CVE-2019-8598, CVE-2019-8602, and CVE-2019-8577. The reference does not explicitly anchor the date of Apple's assignment beyond the 2019 CVE identifiers.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.