CVE-2014-4492: High severity iphone os vulnerability
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4492?
CVE-2014-4492 is considered a high severity vulnerability due to its potential to allow execution of arbitrary code.
How do I fix CVE-2014-4492?
To fix CVE-2014-4492, users should update their Apple devices to the latest software version that is not vulnerable.
What products are affected by CVE-2014-4492?
CVE-2014-4492 affects Apple iOS versions before 8.1.3, OS X versions before 10.10.2, and tvOS versions before 7.0.3.
What kind of attack can exploit CVE-2014-4492?
CVE-2014-4492 can be exploited through crafted XPC messages sent from a sandboxed app, leading to arbitrary code execution.
Is there a workaround for CVE-2014-4492?
There are no documented workarounds for CVE-2014-4492; the best mitigation is to apply software updates.