Lucene search

K
zdiIan Beer of Google Project ZeroZDI-14-120
HistoryMay 02, 2014 - 12:00 a.m.

(Pwn2Own\Pwn4Fun) Apple OS X IOKit Kernel Information Disclosure Vulnerability

2014-05-0200:00:00
Ian Beer of Google Project Zero
www.zerodayinitiative.com
15

0.03 Low

EPSS

Percentile

90.9%

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Apple OS X. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within IOKit. The issue lies in the storage of kernel pointers in an object’s data structure that could be retrieved from userland. An attacker can leverage this vulnerability to leak kernel pointers.

0.03 Low

EPSS

Percentile

90.9%