vendor:
IOBluetoothHCIController
by:
@rpaleari and @joystick
7.8
CVSS
HIGH
Missing Check
787
CWE
Product Name: IOBluetoothHCIController
Affected Version From: Mac OS X Yosemite (10.10)
Affected Version To: Mac OS X Yosemite (10.10)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X Yosemite (10.10)
2020
IOBluetoothHCIController::TransferACLPacketToHW() Panic Exploit
This exploit is written for Mac OS X Yosemite (10.10) by @rpaleari and @joystick. It exploits a missing check in IOBluetoothHCIController::TransferACLPacketToHW() to trigger a panic. The exploit uses IOConnectCallMethod to call DispatchHCISendRawACLData().
Mitigation:
Ensure that all checks are in place and that all input is properly validated.