CVE-2015-7068 is a critical vulnerability affecting Apple iOS, OS X, tvOS, and watchOS, specifically within the IOKit SCSI component. An attacker can exploit this flaw by providing an unspecified userclient type via a malicious application, leading to arbitrary code execution in a privileged context or a denial of service through a NULL pointer dereference. With a CVSS score of 7.8 (High), this vulnerability presents a significant risk due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is public exploit code available on ExploitDB demonstrating a kernel NULL dereference. Despite its severity, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 2.1CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
< 9.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 10.11.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.