CVE-2015-1061 describes a type confusion vulnerability in IOSurface affecting Apple iOS before 8.2, OS X through 10.10.2, and Apple TV before 7.1. This flaw allows a crafted application to execute arbitrary code with elevated privileges during serialized-object handling. With a CVSS score of 9.3, this vulnerability is critical, requiring medium attack complexity but allowing remote exploitation to achieve full confidentiality, integrity, and availability compromise. There is no evidence of active exploitation, nor are public exploit modules like Metasploit or Nuclei available. However, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0.3CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
<= 8.1.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.10.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.