VYPR
Unrated severityNVD Advisory· Published Mar 12, 2015· Updated May 6, 2026

CVE-2015-1066

CVE-2015-1066

Description

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Off-by-one error in Apple IOAcceleratorFamily allows privilege escalation; fixed in Security Update 2015-002.

Vulnerability

CVE-2015-1066 is an off-by-one error in the IOAcceleratorFamily component of Apple OS X through version 10.10.2. This bug affects OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, and OS X Yosemite v10.10.2. The vulnerability is triggered by a crafted application, leading to a memory corruption issue due to improper bounds checking [1].

Exploitation

An attacker must convince a user to run a malicious application on the affected system. The off-by-one error in IOAcceleratorFamily leads to an out-of-bounds memory access, which can be exploited to achieve arbitrary code execution in a privileged context. No user interaction beyond launching the app is required [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code with system privileges, resulting in full compromise of the affected OS X system. The attacker gains the ability to install software, modify system files, and access sensitive data [1].

Mitigation

Apple addressed CVE-2015-1066 in Security Update 2015-002, released on March 9, 2015. The fix is available for OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, and OS X Yosemite v10.10.2. Users are advised to install the update immediately. No workarounds are available [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.