CVE-2015-3794
Description
The Speech UI in Apple OS X before 10.10.5, when speech alerts are enabled, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Unicode string.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory corruption vulnerability in OS X Speech UI allows remote code execution via a crafted Unicode string when speech alerts are enabled.
Vulnerability
The Speech UI component in Apple OS X Yosemite versions 10.10 through 10.10.4, when speech alerts are enabled, contains a memory corruption vulnerability. A remote attacker can trigger the issue by delivering a crafted Unicode string to the system, leading to memory corruption. The vulnerability is addressed in OS X Yosemite 10.10.5 [1].
Exploitation
An attacker does not require authentication or local access. The victim must have speech alerts enabled (a system preference). The attacker can deliver the malicious Unicode string via a web page, email, or other means that causes the Speech UI to process the string. When the system attempts to handle the crafted Unicode data, a memory corruption occurs, potentially allowing code execution or causing a crash.
Impact
Successful exploitation allows a remote attacker to execute arbitrary code in the context of the Speech UI process, or cause a denial of service via application crash. The exact privilege level is not specified, but code execution could lead to further system compromise.
Mitigation
Apple released OS X Yosemite 10.10.5 on August 13, 2015, which includes a fix for this vulnerability [1]. Users should update to OS X 10.10.5 or later. No workaround is available if speech alerts are required; disabling speech alerts may reduce exposure but is not a complete mitigation.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.10.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlnvdVendor Advisory
- support.apple.com/kb/HT205031nvdVendor Advisory
- www.securityfocus.com/bid/76340nvd
- www.securitytracker.com/id/1033276nvd
News mentions
0No linked articles in our index yet.