The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
| Software | From | Fixed in |
|---|---|---|
| apple / iphone_os | 8.0 | 8.0.x |
| apple / iphone_os | 8.0.1 | 8.0.1.x |
| apple / iphone_os | 8.0.2 | 8.0.2.x |
| apple / iphone_os | - | 8.1.x |
| apple / mac_os_x | 10.10.0 | 10.10.0.x |
| apple / mac_os_x | - | 10.10.1.x |
| apple / mac_os_x | 10.9.5 | 10.9.5.x |
| apple / mac_os_x | 10.8.5 | 10.8.5.x |
| apple / tvos | 6.0 | 6.0.x |
| apple / tvos | 6.0.1 | 6.0.1.x |
| apple / tvos | 6.0.2 | 6.0.2.x |
| apple / tvos | 6.1 | 6.1.x |
| apple / tvos | 6.1.1 | 6.1.1.x |
| apple / tvos | 6.1.2 | 6.1.2.x |
| apple / tvos | 6.2 | 6.2.x |
| apple / tvos | 6.2.1 | 6.2.1.x |
| apple / tvos | 7.0 | 7.0.x |
| apple / tvos | - | 7.0.1.x |