CVE-2015-6979Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
9.3CRITICALNVD
EPSS
1.5%
top 19.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 17

Description

GasGauge in Apple iOS before 9.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDapple/watchos2.0
NVDapple/iphone_os9.0.2
Appleapple/ios9.1
Appleapple/watchos2.1

🔴Vulnerability Details

1
GHSA
GHSA-p9j2-q9cx-4gh7: GasGauge in Apple iOS before 92022-05-17

📋Vendor Advisories

2
Apple
CVE-2015-6979: watchOS 2.1
Apple
CVE-2015-6979: iOS 9.1