cbcvebase.
CVE-2015-1061
published 2015-03-12

CVE-2015-1061: IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a…

PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.21%
89.8th percentile
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleabout_security_update_2015-002
appleabout_security_update_2015-003
appleapple_tv
appleios
appleiphone_os<= 8.1.3
applemac_os_x<= 10.10.2
appletvos<= 7.0.3

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.