CVE-2019-6225 is a memory corruption vulnerability in Apple operating systems (iOS, macOS, tvOS) that could allow a malicious application to elevate its privileges. The issue was addressed by Apple with improved validation in iOS 12.1.3, macOS Mojave 10.14.3, and tvOS 12.1.2. The vulnerability is due to insufficient validation of memory operations, which could be exploited by a local attacker running a malicious application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit for macOS (CVE-2019-6225), targeting versions 10.14.2 and earlier. The exploit is implemented in Objective-C (main file: exp.m) and relies on manipulating kernel memory via the IOSurfaceRoot IOKit service. The exploit achieves root privileges by crafting fake kernel objects, obtaining a fake kernel task port (tfp0), and modifying the current process's credentials in kernel memory. Upon success, it spawns a root shell (/bin/sh). The exploit will crash the machine if run a second time, and it does not work on systems with SMAP enabled. The code is based on prior public research and exploits, and is operational with a hardcoded payload for privilege escalation. The repository includes a Makefile for building the exploit, a header file (exp.h) with kernel structure definitions, and a README describing usage and limitations.
This repository is an iOS 12 jailbreak exploit targeting CVE-2019-6225 (voucher_swap), affecting iOS 12.0 to 12.1.2 on 16K page size devices. The exploit is implemented as an Xcode project with Objective-C and C code, structured into several components: - The core exploit (voucher_swap) is based on Brandon Azad's public exploit for CVE-2019-6225, which abuses a use-after-free in the Mach voucher subsystem to gain kernel read/write (tfp0). - The exploit chain is orchestrated in 'beginOsiris.c' and 'ViewController.m', which handle device checks, exploit execution, privilege escalation to root, sandbox escape, and demonstration of kernel access by writing a file to '/var/mobile/Media/Downloads/'. - The project includes utility code for kernel memory manipulation, offset management, and device compatibility. - The exploit does not install a full jailbreak environment but provides the essential primitives (tfp0, root, sandbox escape) for further development. - The code is modular, with clear separation between the exploit, kernel utilities, and UI components. The exploit is operational and demonstrates successful exploitation by writing a file outside the sandbox and respringing the device. It is intended for developers and researchers, not for general public use. No network endpoints or remote attack vectors are present; the exploit is local and requires code execution on the target device.
This repository implements a proof-of-concept (POC) jailbreak exploit for iOS 12.0 to 12.1.2, targeting CVE-2019-6225 (the voucher_swap vulnerability). The exploit is designed for developer use and is not a full jailbreak for end users. The codebase is structured as an Xcode project with Objective-C and C source files, including a GUI front-end and a set of kernel exploitation utilities. The main exploit logic is in the 'voucher_swap' module, which leverages a use-after-free in the task_swap_mach_voucher() kernel routine to obtain arbitrary kernel read/write via a fake kernel task port (tfp0). The exploit then escalates privileges to root, escapes the application sandbox, writes a test file to /var/mobile/Media/Downloads/ to demonstrate the escape, and triggers a respring. The code includes device and iOS version checks, and only supports 16K page size devices (A12 and similar). The repository contains 69 files, with about 40 code files in Objective-C and C, and is organized into modules for kernel utilities, offsets, patch finding, and the main exploit logic. No network endpoints or remote attack vectors are present; the exploit is entirely local and requires execution on the target device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.