CVE-2014-4421: Low severity Apple iOS and macOS vulnerability
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4420.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4421?
CVE-2014-4421 has been classified as a high severity vulnerability due to its ability to expose sensitive memory content.
How do I fix CVE-2014-4421?
To fix CVE-2014-4421, users should upgrade their affected devices to a version of iOS or TVOS that is 8 or later for iOS and 7 or later for tvOS.
What types of devices are affected by CVE-2014-4421?
CVE-2014-4421 affects several Apple devices, including iPhones running iOS versions prior to 8 and Apple TVs running tvOS versions prior to 7.
Can CVE-2014-4421 be exploited remotely?
CVE-2014-4421 requires local access through a crafted application, so it is not inherently a remote exploit.
What impact does CVE-2014-4421 have on users?
The impact of CVE-2014-4421 includes the potential for attackers to access sensitive memory content, which can lead to unauthorized data exposure.