PT-2017-2792 · Apple · Ios

Ben Seri

+1

·

Published

2017-09-12

·

Updated

2019-05-14

·

CVE-2017-14315

CVSS v2.0

7.9

High

VectorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple iOS versions 7 through 9
Description The issue is related to a flaw in the implementation of the Low Energy Audio Protocol (LEAP) in Apple iOS, which can lead to a heap overflow with attacker-controlled data when a large audio command is sent to a targeted device. This overflow can be exploited by an attacker to gain full control of the device, leveraging the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control but requires the default "Bluetooth On" value to be present in Settings.
Recommendations For Apple iOS versions 7 through 9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02055
CVE-2017-14315

Affected Products

Ios