VYPR
Unrated severityNVD Advisory· Published Oct 23, 2015· Updated May 6, 2026

CVE-2015-7035

CVE-2015-7035

Description

Apple Mac EFI before 2015-002, as used in OS X before 10.11.1 and other products, mishandles arguments, which allows attackers to reach "unused" functions via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apple Mac EFI mishandles arguments, allowing attackers to reach unused functions; addressed in EFI Security Update 2015-002 and OS X 10.11.1.

Vulnerability

Apple Mac EFI firmware, as used in OS X before 10.11.1 and other products, contains an argument-handling issue that allows attackers to reach unused functions. The affected versions include OS X El Capitan 10.11, OS X Yosemite v10.10.5, and OS X Mavericks v10.9.5. The vulnerability is addressed in Mac EFI Security Update 2015-002 and OS X El Capitan 10.11.1 [1], [2].

Exploitation

The official description notes that the issue arises from mishandled arguments, but the precise attack vector and required conditions are not publicly detailed. Based on the available references, exploitation may require local access or proximity, and possibly physical presence, as EFI vulnerabilities often do. The MITRE researchers who reported the vulnerability are noted in the advisory [2].

Impact

An attacker who successfully exploits this issue can exercise unused EFI functions, which could lead to arbitrary code execution with firmware-level privileges, compromising the initial boot integrity and allowing persistent, stealthy control over the system [2].

Mitigation

Apple released Mac EFI Security Update 2015-002 for OS X Mavericks v10.9.5, and addressed the issue in OS X El Capitan 10.11.1 (and Security Update 2015-004 for Yosemite and Security Update 2015-007 for Mavericks) [1], [2]. Users should apply the latest EFI firmware updates from Apple. No workaround is mentioned.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.