CVE-2014-4489: Null Pointer Dereference
IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly initialize event queues, which allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4489?
CVE-2014-4489 has a high severity level due to the potential for arbitrary code execution and denial of service.
How do I fix CVE-2014-4489?
To mitigate CVE-2014-4489, update affected Apple devices to iOS 8.1.3, OS X 10.10.2, or tvOS 7.0.3 or later.
What versions of software are affected by CVE-2014-4489?
CVE-2014-4489 affects Apple iOS versions prior to 8.1.3, OS X versions before 10.10.2, and tvOS versions before 7.0.3.
What types of attacks are possible with CVE-2014-4489?
CVE-2014-4489 allows attackers to execute arbitrary code or cause a denial of service through a crafted application.
Is there a workaround for CVE-2014-4489?
There is no documented workaround for CVE-2014-4489; updating to the latest software version is recommended.