Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-7047Improper Input Validation in Apple Iphone OS

Severity
7.2HIGHNVD
EPSS
0.7%
top 26.89%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 11
Latest updateMay 14

Description

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages8 packages

NVDapple/tvos9.0
NVDapple/watchos2.0
Appleapple/tvos9.1
Appleapple/watchos2.1
NVDapple/mac_os_x10.11.1

🔴Vulnerability Details

1
GHSA
GHSA-h498-6fjm-8x65: The kernel in Apple iOS before 92022-05-14

💥Exploits & PoCs

5
Exploit-DB
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers2016-01-28
Exploit-DB
Apple Mac OSX Kernel - no-more-senders Use-After-Free2016-01-28
Exploit-DB
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free2016-01-28
Exploit-DB
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free2016-01-28
Exploit-DB
Apple Mac OSX - IOBluetoothHCIPacketLogUserClient Memory Corruption2016-01-28

📋Vendor Advisories

4
Apple
CVE-2015-7047: watchOS 2.1
Apple
CVE-2015-7047: tvOS 9.1
Apple
CVE-2015-7047: iOS 9.2
Apple
CVE-2015-7047: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks