CVE-2014-4377
Description
Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote code execution or denial of service via a crafted PDF document.
Vulnerability
Integer overflow in CoreGraphics, the graphics rendering framework, in Apple iOS versions prior to 8 and Apple TV versions prior to 7. The vulnerability is triggered when parsing a specially crafted PDF document. Affected versions: iOS 7.x and earlier, Apple TV 6.x and earlier.
Exploitation
An attacker can deliver a malicious PDF document to the target device, for example via email, web download, or other means. If the user opens the PDF, the integer overflow in CoreGraphics occurs, leading to memory corruption. No authentication is required beyond user interaction to open the file.
Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the affected application (e.g., MobileSafari or PDF viewer) or cause a denial of service (application crash). This could lead to full device compromise.
Mitigation
Apple addressed the issue in iOS 8 [1] and Apple TV 7 [2]. Users should update their devices to the latest available versions. No workaround is available. The vulnerability is not listed on the CISA KEV as of the publication date.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
20cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <=7.1.2
- cpe:2.3:o:apple:iphone_os:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.4:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.6:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.1.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <=6.2
- cpe:2.3:o:apple:tvos:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:tvos:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:tvos:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:tvos:6.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:tvos:6.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:tvos:6.1.2:*:*:*:*:*:*:*
- Range: <8
- Range: <7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2014-09/0107.htmlnvd
- secunia.com/advisories/61318nvd
- support.apple.com/kb/HT6441nvd
- support.apple.com/kb/HT6442nvd
- support.apple.com/kb/HT6443nvd
- www.securityfocus.com/bid/69882nvd
- www.securityfocus.com/bid/69903nvd
- www.securitytracker.com/id/1030866nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/96076nvd
News mentions
0No linked articles in our index yet.