CVE-2014-4404
KEVmassHeap-Based Buffer Overflow in Apple IOHIDFamily (OS X, iOS, Apple TV)
CISA: Apple OS X Heap-Based Buffer Overflow Vulnerability
CVE-2014-4404 is a heap-based buffer overflow (CWE-119) in the IOHIDFamily component of Apple OS X, and the flaw also affects iOS versions before 8 and Apple TV software before 7. IOHIDFamily is the OS X/iOS kernel component that handles Human Interface Device (HID) processing; the source data does not specify the exact trigger, but the overflow occurs when this kernel component handles crafted HID-related input or data. A successful attacker gains the ability to execute arbitrary code in a privileged context, effectively kernel-level privileges on the affected device. Affected populations are Apple OS X systems (per CISA), iOS devices running iOS 7 or earlier, and Apple TV units on software prior to version 7. Exploitation is confirmed in the wild: the flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 49% probability of exploitation in the next 30 days (99th percentile).
What to do: Apply updates per vendor instructions: upgrade iOS devices to iOS 8 or later and Apple TV to software 7 or later, and ensure Macs run an OS X build containing Apple's IOHIDFamily fix (verify against Apple's security update list, as the source data does not name the fixed OS X version). Inventory your estate for legacy iOS, Apple TV, and OS X installations, since these are 2014-era version ranges and the flaw is on CISA's KEV list, which mandates remediation per vendor instructions. Treat kernel-level code execution as full device compromise when triaging any suspected exploitation.
| Apple OS X | — |
| Apple iOS | before 8 |
| Apple TV | before 7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
- Affected
- Apple OS X
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Apple
- Products
- OS X
- Weakness
- CWE-119