First published: Fri Jan 30 2015(Updated: )
Integer signedness error in IOBluetoothFamily in the Bluetooth implementation in Apple OS X before 10.10 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (write to kernel memory) via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4497 is considered a high severity vulnerability due to its potential for arbitrary code execution in a privileged context.
To fix CVE-2014-4497, update your Apple OS X to version 10.10 or later where the vulnerability has been addressed.
CVE-2014-4497 affects Apple OS X versions prior to 10.10, specifically versions up to and including 10.9.5.
Attackers can exploit CVE-2014-4497 to execute arbitrary code or cause a denial of service by manipulating Bluetooth connections.
There are no widely recognized workarounds for CVE-2014-4497; upgrading the system is the best approach.