CVE-2015-3702
Description
Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3701.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in the Intel Graphics Driver on Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors.
Vulnerability
A buffer overflow vulnerability exists in the Intel Graphics Driver bundled with Apple OS X before version 10.10.4. The affected component is the graphics driver, and the issue can be triggered by a local user through unspecified vectors. The vulnerability is distinct from similar issues tracked as CVE-2015-3695 through CVE-2015-3701. Versions affected include OS X Mavericks v10.9.5 and OS X Yosemite v10.10 through v10.10.3 [1].
Exploitation
Exploitation requires local access to the system. The exact sequence of steps is not disclosed in the available references, but it involves providing crafted input to the Intel Graphics Driver that triggers the buffer overflow. The attacker does not need any special privileges to initiate the attack, as the vulnerability can be triggered from a non-privileged user context [1].
Impact
Successful exploitation allows a local attacker to gain elevated privileges on the system. Since the Intel Graphics Driver runs with kernel-level privileges, the attacker can achieve arbitrary code execution in kernel mode, leading to full compromise of the affected Mac [1].
Mitigation
Apple addressed this vulnerability in OS X Yosemite v10.10.4 and Security Update 2015-005. Users should update to the latest available version of OS X. No workarounds are documented in the references, and the vendor recommends applying the security update as soon as possible [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.10.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlnvdPatchVendor Advisory
- support.apple.com/kb/HT204942nvdVendor Advisory
- www.securityfocus.com/bid/75493nvd
- www.securitytracker.com/id/1032760nvd
News mentions
0No linked articles in our index yet.