CVE-2014-4495: Critical severity iphone os vulnerability
The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4495?
CVE-2014-4495 has a medium severity rating due to the potential for attackers to bypass access restrictions.
How do I fix CVE-2014-4495?
To fix CVE-2014-4495, update your Apple iOS to version 8.1.3 or later, macOS to version 10.10.2 or later, and tvOS to version 7.0.3 or later.
What versions are affected by CVE-2014-4495?
CVE-2014-4495 affects iOS versions prior to 8.1.3, macOS versions before 10.10.2, and tvOS versions before 7.0.3.
Can exploiting CVE-2014-4495 enable remote code execution?
Exploiting CVE-2014-4495 can potentially allow for unauthorized access but does not directly lead to remote code execution.
What type of vulnerability is CVE-2014-4495?
CVE-2014-4495 is a permissive access control vulnerability in the kernel related to shared memory segments.