First published: Fri Sep 18 2015(Updated: )
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | =1.0 | |
Apple iOS and macOS | <=10.10.5 | |
iOS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5882 is considered a critical vulnerability that allows local users to bypass entitlement protections.
The best way to mitigate CVE-2015-5882 is to update to the latest version of iOS, macOS, or watchOS that addresses this vulnerability.
CVE-2015-5882 affects users of Apple iPhone OS before version 8.4.2, macOS Yosemite up to 10.10.5, and watchOS 1.0.
The implications of CVE-2015-5882 include unauthorized access to the task ports of other processes, potentially leading to privilege escalation.
No effective workaround exists for CVE-2015-5882; upgrading to a patched version is strongly recommended.