CVE-2015-5866
Description
IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IOHIDFamily in Apple OS X before 10.11 allows local attackers to execute arbitrary code in kernel context or cause denial of service via a crafted app.
Vulnerability
IOHIDFamily, the kernel extension responsible for handling Human Interface Device (HID) events in Apple OS X, contains a memory corruption vulnerability. This issue affects OS X versions prior to 10.11 (El Capitan). The vulnerability can be triggered by a crafted application that interacts with the IOHIDFamily interface, leading to memory corruption. [1]
Exploitation
An attacker must have the ability to run a malicious application on the target system. No additional privileges are required beyond local user access. The crafted app sends specially crafted input to the IOHIDFamily kernel extension, exploiting the memory corruption flaw. The exact sequence of steps is not publicly detailed, but the attack vector is local execution of the malicious app.
Impact
Successful exploitation allows the attacker to execute arbitrary code in a privileged kernel context, gaining full system control. Alternatively, the attacker can cause a denial of service through memory corruption, crashing the system. The compromise is at the highest privilege level (kernel).
Mitigation
Apple addressed this vulnerability in OS X El Capitan v10.11, released on September 30, 2015. Users should upgrade to OS X 10.11 or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlnvdVendor Advisory
- www.securityfocus.com/bid/76908nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1033703nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT205267nvdVendor Advisory
News mentions
0No linked articles in our index yet.