VYPR
High severity7.3NVD Advisory· Published Apr 10, 2015· Updated May 6, 2026

CVE-2015-1098

CVE-2015-1098

Description

A memory corruption vulnerability in Apple iWork allows remote code execution or denial of service via a crafted iWork file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A memory corruption vulnerability in Apple iWork allows remote code execution or denial of service via a crafted iWork file.

Vulnerability

A memory corruption vulnerability exists in Apple iWork on iOS before 8.3 and OS X before 10.10.3. The bug is triggered when a user opens a specially crafted iWork file (e.g., Pages, Numbers, or Keynote document). No special configuration is required beyond having iWork installed. The issue is present in all versions prior to the fixes released in iOS 8.3 and OS X Yosemite 10.10.3 [1][2].

Exploitation

An attacker can exploit this vulnerability by delivering a malicious iWork file to the target user, typically via email, web download, or messaging. The user must open the file in iWork on an affected device. No authentication or special network position is required; the attack is remote and user interaction is limited to opening the file. The exact exploitation steps are not publicly detailed, but the memory corruption can be leveraged to execute arbitrary code [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user, or cause a denial of service via application crash or system instability. On iOS, this could lead to full device compromise; on OS X, it could lead to arbitrary code execution within the user's session. The impact is high due to the potential for remote code execution without authentication [1][2].

Mitigation

Apple addressed this vulnerability in iOS 8.3 and OS X Yosemite 10.10.3, released on April 8, 2015. Users should update their devices to these or later versions. No workarounds are available; the only mitigation is to apply the security updates. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1][2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.