First published: Fri Jan 30 2015(Updated: )
Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segment in a path.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8828 is considered a moderate severity vulnerability that can allow unauthorized write access to the sandbox-profile cache.
To fix CVE-2014-8828, update your macOS to version 10.10 or later, where the vulnerability has been resolved.
CVE-2014-8828 affects macOS versions before 10.10, specifically versions up to and including 10.9.5.
Attackers can exploit CVE-2014-8828 to write malicious data to the sandbox-profile cache via a compromised sandboxed application.
If you are using macOS versions earlier than 10.10, your system is at risk from CVE-2014-8828 unless patched.