CVE-2015-7072: Input Validation
dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7072?
CVE-2015-7072 is considered a high severity vulnerability due to its potential to allow execution of arbitrary code in a privileged context.
How do I fix CVE-2015-7072?
To fix CVE-2015-7072, update your device to iOS version 9.2 or later, tvOS version 9.1 or later, or watchOS version 2.1 or later.
What versions of Apple OS are affected by CVE-2015-7072?
CVE-2015-7072 affects iOS versions prior to 9.2, tvOS versions prior to 9.1, and watchOS versions prior to 2.1.
Can CVE-2015-7072 be exploited remotely?
CVE-2015-7072 requires a crafted app to be installed on the device, meaning exploitation cannot occur remotely without user interaction.
What are the potential impacts of CVE-2015-7072?
Exploitation of CVE-2015-7072 could allow an attacker to execute arbitrary code with elevated privileges, compromising device security.