EIP-2026-104549

PRE-CVE

Apple Mac OSX (Mavericks) - 'IOBluetoothHCIUserClient' Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104549. PoCs published by rpaleari & joystick.

AI-analyzed exploit summary This exploit targets a missing sign check in IOBluetoothHCIUserClient::SimpleDispatchWL() on Mac OS X Mavericks (10.9.4/10.9.5). It leverages a kernel memory corruption vulnerability to achieve arbitrary code execution by manipulating an index value to redirect execution to a controlled memory location.

Description

Apple Mac OSX (Mavericks) - 'IOBluetoothHCIUserClient' Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by rpaleari & joystick · cdososx
https://www.exploit-db.com/exploits/35153

This exploit targets a missing sign check in IOBluetoothHCIUserClient::SimpleDispatchWL() on Mac OS X Mavericks (10.9.4/10.9.5). It leverages a kernel memory corruption vulnerability to achieve arbitrary code execution by manipulating an index value to redirect execution to a controlled memory location.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Mac OS X Mavericks (10.9.4/10.9.5) IOBluetoothHCIUserClient
No auth needed
Prerequisites: Access to a vulnerable Mac OS X Mavericks system · Compilation with IOKit framework
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026