CVE-2014-4492
Apple iOS <8.1.3, OS X <10.10.2, TV <7.0.3 - RCE
Title source: llmDescription
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · clocalosx
https://www.exploit-db.com/exploits/35847
References (10)
Scores
EPSS
0.2434
EPSS Percentile
96.0%
Classification
CWE
CWE-19
Status
draft
Affected Products (3)
apple/iphone_os
< 8.1.2
apple/mac_os_x
< 10.10.1
apple/tvos
< 7.0.1
Timeline
Published
Jan 30, 2015
Tracked Since
Feb 18, 2026