ZeroHour

CVE-2014-4404

KEVmass

Heap-Based Buffer Overflow in Apple IOHIDFamily (OS X, iOS, Apple TV)

CISA: Apple OS X Heap-Based Buffer Overflow Vulnerability

CVSS
EPSS
49%p99
Published
KEV added
AI analysis

CVE-2014-4404 is a heap-based buffer overflow (CWE-119) in the IOHIDFamily component of Apple OS X, and the flaw also affects iOS versions before 8 and Apple TV software before 7. IOHIDFamily is the OS X/iOS kernel component that handles Human Interface Device (HID) processing; the source data does not specify the exact trigger, but the overflow occurs when this kernel component handles crafted HID-related input or data. A successful attacker gains the ability to execute arbitrary code in a privileged context, effectively kernel-level privileges on the affected device. Affected populations are Apple OS X systems (per CISA), iOS devices running iOS 7 or earlier, and Apple TV units on software prior to version 7. Exploitation is confirmed in the wild: the flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 49% probability of exploitation in the next 30 days (99th percentile).

What to do: Apply updates per vendor instructions: upgrade iOS devices to iOS 8 or later and Apple TV to software 7 or later, and ensure Macs run an OS X build containing Apple's IOHIDFamily fix (verify against Apple's security update list, as the source data does not name the fixed OS X version). Inventory your estate for legacy iOS, Apple TV, and OS X installations, since these are 2014-era version ranges and the flaw is on CISA's KEV list, which mandates remediation per vendor instructions. Treat kernel-level code execution as full device compromise when triaging any suspected exploitation.

Affected
Apple OS X
Apple iOSbefore 8
Apple TVbefore 7
Estimated exposure
massmillions of Apple devices (legacy Macs, iPhones/iPads on iOS ≤7, and Apple TV units on pre-7 software) — Apple's installed base at disclosure (2014) was on the order of hundreds of millions of iOS devices and tens of millions of Macs, so even a small legacy share of devices still running pre-8 iOS or unpatched OS X runs into the millions; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.

CISA Known Exploited Vulnerability
Affected
Apple OS X
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Apple
Products
OS X
Weakness
CWE-119

In the news