CVE-2015-6996

Apple iOS <9.1, macOS <10.11.1, watchOS <2.0.1 - Remote Code Execution via IOAcceleratorFamily Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-6996. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a NULL pointer dereference in IOAccelContext2::connectClient due to unchecked return value of OSMetaClassBase::safeMetaCast, leading to kernel memory corruption and potential privilege escalation on OS X 10.10.5.

Description

IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · cdososx
https://www.exploit-db.com/exploits/39380

This exploit leverages a NULL pointer dereference in IOAccelContext2::connectClient due to unchecked return value of OSMetaClassBase::safeMetaCast, leading to kernel memory corruption and potential privilege escalation on OS X 10.10.5.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Apple OS X 10.10.5 (IOAcceleratorFamily2)
No auth needed
Prerequisites: Access to a vulnerable macOS system with Intel GPU
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205375
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Oct/msg00003.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205370
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205378
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033929

Scores

EPSS 0.0673
EPSS Percentile 91.5%

Details

CWE
CWE-119
Status published
Products (3)
apple/iphone_os < 9.0.2
apple/mac_os_x < 10.11.0
apple/watchos < 2.0.0
Published Oct 23, 2015
Tracked Since Feb 18, 2026