vendor:
iOS
by:
Google Security Research
8.1
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: iOS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2016-XXXX
CPE: a:apple:ios
Platforms Tested: iOS
2016
IOHIDLibUserClient _startQueue Method Vulnerability
The _startQueue method in IOHIDLibUserClient allows an attacker to trigger a memory corruption vulnerability by manipulating the _currentEntrySize and _maxEntrySize variables. This can lead to a potential arbitrary code execution.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the vendor-provided patch or update to a version where the issue is fixed. Additionally, it is advisable to only use trusted HID devices and avoid connecting untrusted devices.