First published: Fri Dec 11 2015(Updated: )
AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=9.0 | |
iStyle @cosme iPhone OS | <=9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7055 is considered a high severity vulnerability due to its potential to allow attackers to execute arbitrary code with elevated privileges.
CVE-2015-7055 exploits a flaw in AppleMobileFileIntegrity that permits unauthorized changes to access-control structures.
CVE-2015-7055 affects Apple iOS versions prior to 9.2 and tvOS versions prior to 9.1.
To fix CVE-2015-7055, users should update their iOS and tvOS to the latest versions released by Apple.
Failure to address CVE-2015-7055 could lead to unauthorized applications executing code in a privileged context, potentially compromising user data.