CVE-2015-7046: Infoleak
The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7046?
CVE-2015-7046 is considered a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2015-7046?
To fix CVE-2015-7046, update your affected Apple operating systems to their latest versions.
Which versions are affected by CVE-2015-7046?
CVE-2015-7046 affects Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1.
What is the impact of CVE-2015-7046?
The impact of CVE-2015-7046 allows attackers to bypass ASLR protection, potentially executing malicious code with root privileges.
Can attackers exploit CVE-2015-7046 remotely?
Exploitation of CVE-2015-7046 requires a crafted app to be installed on the device, making it less likely for remote exploitation.