Google warns about two iOS zero-day vulnerabilities that hackers have been actively exploiting; the vulnerabilities have been fixed in iOS 12.1.4
Update Your iPhone Now Tweets: Ben Hawkes / @benhawkes : CVE-2019-7286 and CVE-2019-7287 in the iOS advisory today (http://support.apple.com/...) were exploited in the wild as 0day. Thomas Brewster / @iblametom : New - Google researchers say iOS bugs were abused in the wild. No one is saying anything about what happened, but it's landed on the same day as the FaceTime fix, so update your iPhone. Now. https://www.forbes.com/... Ed Bott / @edbott : Oh nothing, just “two iOS zero-day vulnerabilities that hackers have been actively exploiting.” [Whistles] http://twitter.com/... Steve Troughton-Smith / @stroughtonsmith : What about the security implications of doxxing a 14 year old on http://apple.com/? http://twitter.com/...
Context & Ripple Effects
Google's Ben Hawkes flagged CVE-2019-7286 and CVE-2019-7287 as exploited in the wild before any patch existed, forcing Apple's iOS 12.1.4 release — and the disclosure landed the same day as the FaceTime eavesdropping fix, compounding pressure on iPhone users to update immediately. What makes this 2019 episode notable in hindsight is that it was an early instance of a pattern the related coverage keeps confirming: Apple later patched three 0-days in one iOS 14.4 update, confirmed a WebKit zero-day found and reported by Google in iOS 16.1.2, and by late 2023 had reached twenty zero-days patched in a single year via emergency updates across iOS, iPadOS, and macOS.
First-order effects
- iPhone users on unpatched builds are exposed to two actively exploited flaws until they install iOS 12.1.4, while Apple ships fixes without explaining what the in-the-wild attacks actually did.
Second-order effects
- Google's role as the disclosing researcher sets up a recurring dynamic — its later WebKit find shows it kept surfacing iOS flaws — pushing Apple into a rhythm of reactive emergency releases rather than scheduled ones.
Third-order effects
- If the cadence holds, in-the-wild iOS zero-day exploitation becomes a routine operating condition for Apple, making rapid patch adoption and third-party research disclosure structural features of mobile platform security rather than exceptional events.
The trend: Apple is settling into a standing cycle of externally reported, actively exploited iOS zero-days met with emergency patches — a pattern this 2019 disclosure helped establish.