CVE-2015-1145
Description
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OS X Code Signing validation flaw allows local users to bypass sandbox restrictions via a crafted bundle.
Vulnerability
CVE-2015-1145 is a signature validation flaw in the Code Signing implementation of Apple OS X prior to version 10.10.3. The bug allows a specially crafted bundle to bypass access restrictions enforced by code signing. Affected versions include OS X Yosemite v10.10 through v10.10.2. This is distinct from the related CVE-2015-1146 [1].
Exploitation
A local user with the ability to craft and run a malicious bundle can exploit this vulnerability. No special privileges or network access are required beyond local code execution capability. The attacker constructs a bundle that exploits the improper signature validation to circumvent the intended access restrictions.
Impact
Successful exploitation allows a local attacker to bypass code signing requirements, potentially gaining access to resources or capabilities that should be restricted by the sandbox or other security policies. This can lead to unauthorized information disclosure or privilege escalation within the context of the user's session.
Mitigation
Apple addressed this vulnerability in OS X Yosemite v10.10.3 and Security Update 2015-004. Users should update to the latest available version of OS X. No workarounds are listed in the advisory [1]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.10.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/73982nvdExploitThird Party AdvisoryVDB Entry
- lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlnvdVendor Advisory
- www.securitytracker.com/id/1032048nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT204659nvdVendor Advisory
News mentions
0No linked articles in our index yet.