CVE-2015-3707
Description
The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A NULL pointer dereference in the IOFireWireFamily driver allows local attackers to execute arbitrary code in the kernel context on OS X before 10.10.4.
Vulnerability
The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 contains a NULL pointer dereference vulnerability. A crafted application can trigger this issue, allowing an attacker to execute arbitrary code in a privileged kernel context or cause a denial of service [1]. Affected versions: OS X Yosemite v10.10 through v10.10.3 and OS X Mavericks v10.9.5 [1].
Exploitation
An attacker must have the ability to run a crafted app on the target system. The app interacts with the FireWire driver to trigger a NULL pointer dereference. The attacker needs local access and the ability to execute arbitrary code as a user; no additional privileges or specific hardware are required [1].
Impact
Successful exploitation leads to arbitrary code execution in the kernel context, giving the attacker full system control, or a denial of service due to the NULL pointer dereference. The attacker can gain root privileges and bypass system security mechanisms [1].
Mitigation
The vulnerability is fixed in OS X Yosemite v10.10.4 and Security Update 2015-005, released on June 30, 2015. Users should update via Software Update or the Apple Support downloads. No workaround is available [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.10.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlnvdPatchVendor Advisory
- support.apple.com/kb/HT204942nvdVendor Advisory
- www.securityfocus.com/bid/75493nvd
- www.securitytracker.com/id/1032760nvd
News mentions
0No linked articles in our index yet.