CVE-2014-4492

Apple iOS <8.1.3, OS X <10.10.2, TV <7.0.3 - RCE

Title source: llm

Description

libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · clocalosx
https://www.exploit-db.com/exploits/35847

Scores

EPSS 0.2434
EPSS Percentile 96.0%

Classification

CWE
CWE-19
Status draft

Affected Products (3)

apple/iphone_os < 8.1.2
apple/mac_os_x < 10.10.1
apple/tvos < 7.0.1

Timeline

Published Jan 30, 2015
Tracked Since Feb 18, 2026