header-logo
Suggest Exploit
vendor:
OS X and iOS
by:
Not specified
7.5
CVSS
HIGH
Panic Log Vulnerability
20
CWE
Product Name: OS X and iOS
Affected Version From: OS X and iOS versions prior to the patched versions mentioned in the advisories
Affected Version To: Not specified
Patch Exists: YES
Related CWE: Not specified
CPE: o:apple:mac_os_x (for OS X), cpe:/o:apple:iphone_os (for iOS)
Metasploit:
Other Scripts:
Platforms Tested: Not specified
Not specified

Apple OS X and iOS Panic Log Vulnerability

This vulnerability allows an attacker to cause a panic in the OS X and iOS operating systems, resulting in a denial of service condition. It can be exploited by sending a specially crafted panic log to the target device. The vulnerability has been identified in OS X and iOS versions prior to the patched versions mentioned in the advisories.

Mitigation:

Apple has released security updates for OS X and iOS to address this vulnerability. Users are advised to update their devices to the latest patched versions.
Source

Exploit-DB raw data:

Source: https://code.google.com/p/google-security-research/issues/detail?id=606

Panic log attached

OS X advisory: https://support.apple.com/en-us/HT205731
iOS advisory: https://support.apple.com/en-us/HT205732


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39361.zip