CVE-2014-4404
apple iphone os, apple mac os x, apple tvos
Published 18 Sept 2014 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
References
- archives.neohapsis.com/archives/bugtraq/2014-09/0106.html · Broken Link
- archives.neohapsis.com/archives/bugtraq/2014-09/0107.html · Broken Link
- archives.neohapsis.com/archives/bugtraq/2014-10/0101.html · Broken Link
- lists.apple.com/archives/security-announce/2015/Apr/msg00001.html · Mailing List, Vendor Advisory
- support.apple.com/kb/HT6441 · Vendor Advisory
- support.apple.com/kb/HT6442 · Vendor Advisory
- www.securityfocus.com/bid/69882 · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/69947 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1030866 · Broken Link, Third Party Advisory, VDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/96111 · Third Party Advisory, VDB Entry
- support.apple.com/HT204659 · Vendor Advisory
- support.apple.com/kb/HT6535 · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-4404 · US Government Resource