CVE-2015-3688
Description
CoreText memory corruption in Apple iOS 8.4 and OS X 10.10.4 allows arbitrary code execution via a crafted text file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CoreText memory corruption in Apple iOS 8.4 and OS X 10.10.4 allows arbitrary code execution via a crafted text file.
Vulnerability
A memory corruption vulnerability exists in Apple's CoreText font and text processing engine, affecting iOS prior to 8.4 and OS X prior to 10.10.4. The bug is triggered when the system parses a specially crafted text file, leading to memory corruption that may be exploited to execute arbitrary code. This is one of several related CoreText issues (CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, CVE-2015-3689) and is fixed in the respective security updates [1][2]. The vulnerability also affects iTunes 12.2 and earlier on Windows 7 and later [3].
Exploitation
An attacker can deliver a malicious text file through vectors such as email, web downloads, or specially crafted documents. No special privileges are required, and the attacker only needs to persuade the user to open the file in an application that uses CoreText for rendering, such as Safari, Mail, or Messages. Once the crafted text file is processed by CoreText, the memory corruption occurs, enabling code execution within the context of the affected application [1][2][3].
Impact
Successful exploitation can lead to unexpected application termination (denial of service) or arbitrary code execution at the privilege level of the user running the application. In a worst-case scenario, this could allow an attacker to install malicious software, access sensitive data, or perform actions on the user's behalf without their knowledge [1][2].
Mitigation
Apple has released fixes for this issue: iOS 8.4 [2], OS X Yosemite v10.10.4 and Security Update 2015-005 [1], and iTunes 12.3 for Windows [3]. Users are advised to update their devices to these or later versions as soon as possible. No workaround is available for unpatched systems.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*range: <=10.10.3
- (no CPE)range: < 10.10.4
- Range: < 8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlnvdPatchVendor Advisory
- lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlnvdPatchVendor Advisory
- lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlnvdPatchVendor Advisory
- support.apple.com/kb/HT204941nvdVendor Advisory
- support.apple.com/kb/HT204942nvdVendor Advisory
- support.apple.com/HT205221nvdVendor Advisory
- www.securityfocus.com/bid/75491nvd
- www.securitytracker.com/id/1032760nvd
News mentions
0No linked articles in our index yet.