First published: Fri Dec 11 2015(Updated: )
dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=9.0 | |
iStyle @cosme iPhone OS | <=9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7079 has a high severity rating due to its potential to allow attackers to execute arbitrary code in a privileged context.
To fix CVE-2015-7079, update your Apple iOS to version 9.2 or later, or your tvOS to version 9.1 or later.
CVE-2015-7079 affects Apple iOS versions before 9.2 and tvOS versions before 9.1.
CVE-2015-7079 enables attackers to execute arbitrary code by exploiting mishandled segment validation in dyld.
There are no official workarounds for CVE-2015-7079; updating your software is the recommended mitigation.