Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-4492Apple Iphone OS vulnerability

CWE-196 documents4 sources
Severity
7.5HIGHNVD
EPSS
21.8%
top 4.24%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 30
Latest updateMay 14

Description

libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

NVDapple/tvos7.0.1
NVDapple/mac_os_x10.10.1
NVDapple/iphone_os8.1.2
Appleapple/ios8.1.3
Appleapple/apple_tv7.0.3

🔴Vulnerability Details

1
GHSA
GHSA-6qx2-6p7g-rvh5: libnetcore in Apple iOS before 82022-05-14

💥Exploits & PoCs

1
Exploit-DB
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape2015-01-20

📋Vendor Advisories

3
Apple
CVE-2014-4492: Apple TV 7.0.3
Apple
CVE-2014-4492: iOS 8.1.3
Apple
CVE-2014-4492: OS X Yosemite v10.10.2 and Security Update 2015-001