First published: Thu Mar 12 2015(Updated: )
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=7.0.3 | |
iPhone OS | <=8.1.3 | |
Apple iOS and macOS | <=10.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1061 has a high severity rating due to its potential to allow arbitrary code execution in a privileged context.
To mitigate CVE-2015-1061, users should update affected systems to the latest versions of iOS, macOS, or tvOS.
CVE-2015-1061 affects Apple iOS versions up to 8.1.3, macOS Yosemite up to 10.10.2, and tvOS up to 7.0.3.
CVE-2015-1061 is a type confusion vulnerability present in IOSurface that can be exploited through crafted applications.
Yes, successful exploitation of CVE-2015-1061 can lead to arbitrary code execution, which may result in data loss or compromise.