LOW · 2.6

CVE-2015-7046

The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ...

Vulnerability Description

The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with root privileges.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleWatchos<= 2.0
AppleTvos<= 9.0
AppleMac Os X<= 10.11.1
AppleIphone Os<= 9.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7046?

CVE-2015-7046 is a vulnerability with a CVSS score of 2.6 (LOW). The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ...

How severe is CVE-2015-7046?

CVE-2015-7046 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7046?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Watchos, Apple Tvos, Apple Mac Os X, Apple Iphone Os.