CVE-2015-3680
Description
Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3681, and CVE-2015-3682.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory corruption vulnerability in Apple Type Services on OS X before 10.10.4 allows arbitrary code execution or denial of service via a crafted font file.
Vulnerability
A memory corruption vulnerability exists in Apple Type Services (ATS) on Apple OS X Yosemite versions 10.10 through 10.10.3 and OS X Mavericks v10.9.5. The bug is triggered when processing a crafted font file. This issue is distinct from related vulnerabilities CVE-2015-3679, CVE-2015-3681, and CVE-2015-3682 [1].
Exploitation
An attacker can exploit this vulnerability by convincing a user to open a specially crafted font file, for example via a malicious web page or email. No special network position beyond delivering the file is required, and no authentication is needed beyond user interaction [1].
Impact
Successful exploitation leads to arbitrary code execution in the context of the affected application or system, or a denial of service due to memory corruption. The attacker can achieve full system compromise depending on the process privileges [1].
Mitigation
Apple addressed this issue in OS X Yosemite v10.10.4 and Security Update 2015-005 for OS X Mavericks v10.9.5, released on July 1, 2015. Users should update to the latest version. No workarounds were provided by Apple [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.10.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlnvdPatchVendor Advisory
- support.apple.com/kb/HT204942nvdVendor Advisory
- www.securityfocus.com/bid/75493nvd
- www.securitytracker.com/id/1032760nvd
News mentions
0No linked articles in our index yet.