VYPR
Unrated severityNVD Advisory· Published Oct 9, 2015· Updated May 6, 2026

CVE-2015-5866

CVE-2015-5866

Description

IOHIDFamily in Apple OS X before 10.11 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IOHIDFamily in Apple OS X before 10.11 allows local attackers to execute arbitrary code in kernel context or cause denial of service via a crafted app.

Vulnerability

IOHIDFamily, the kernel extension responsible for handling Human Interface Device (HID) events in Apple OS X, contains a memory corruption vulnerability. This issue affects OS X versions prior to 10.11 (El Capitan). The vulnerability can be triggered by a crafted application that interacts with the IOHIDFamily interface, leading to memory corruption. [1]

Exploitation

An attacker must have the ability to run a malicious application on the target system. No additional privileges are required beyond local user access. The crafted app sends specially crafted input to the IOHIDFamily kernel extension, exploiting the memory corruption flaw. The exact sequence of steps is not publicly detailed, but the attack vector is local execution of the malicious app.

Impact

Successful exploitation allows the attacker to execute arbitrary code in a privileged kernel context, gaining full system control. Alternatively, the attacker can cause a denial of service through memory corruption, crashing the system. The compromise is at the highest privilege level (kernel).

Mitigation

Apple addressed this vulnerability in OS X El Capitan v10.11, released on September 30, 2015. Users should upgrade to OS X 10.11 or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.