vendor:
Mac OS X
by:
rpaleari and joystick
7.8
CVSS
HIGH
Out-of-bounds write
787
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X Yosemite (10.10)
Affected Version To: Mac OS X Yosemite (10.10)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X
2020
Crash-Issue1
This exploit is written for Mac OS X Yosemite (10.10) by @rpaleari and @joystick. It exploits a missing check in IOBluetoothHCIUserClient::DispatchHCICreateConnection() causing a panic. It uses IOConnectCallMethod() to call the vulnerable function and causes an out-of-bounds write.
Mitigation:
Update the system to the latest version of Mac OS X.