VYPR
Unrated severityNVD Advisory· Published Oct 9, 2015· Updated May 6, 2026

CVE-2015-5890

CVE-2015-5890

Description

IOGraphics in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Memory corruption in IOGraphics on OS X before 10.11 allows locals to gain privileges or cause denial of service.

Vulnerability

IOGraphics in Apple OS X before 10.11 (El Capitan) contains a memory corruption issue reachable via unspecified vectors. The exact vulnerable code path and required conditions are not disclosed in the available references, but the issue is distinct from related IOGraphics vulnerabilities CVE-2015-5871, CVE-2015-5872, and CVE-2015-5873. Affected versions include Mac OS X 10.6.8 through 10.10.x.

Exploitation

Per the vendor advisory [1], exploitation requires local user access. The attacker must be able to execute code or trigger the IOGraphics interface on the affected system. The vendor did not disclose a concrete sequence of steps.

Impact

A successful attacker can gain elevated privileges or cause a denial of service through memory corruption. The impact includes potential arbitrary code execution at the kernel level, as IOGraphics is a kernel extension, leading to full compromise of system confidentiality, integrity, and availability.

Mitigation

Apple released the fix in OS X 10.11 (El Capitan) as part of the security update detailed in [1]. Users should upgrade to OS X 10.11 or later. No workarounds were provided for unsupported versions. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.