CVE-2014-4476

medium
Published 2015-01-30 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4477 and CVE-2014-4479.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — https://support.apple.com/kb/HT204949

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://support.apple.com/HT204246

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://support.apple.com/HT204245

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://support.apple.com/HT204243

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jun/msg00006.html

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jan/msg00002.html

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html

OS impact

OSVersionStatusFixed in
macos macosaffected

Application impact

VendorProductVersionsFixed
applesafari{"endIncluding":"6.2.2"}
applesafari7.0
applesafari7.0.1
applesafari7.0.2
applesafari7.0.3
applesafari7.0.4
applesafari7.0.5
applesafari7.0.6
applesafari7.1.0
applesafari7.1.1
applesafari7.1.2
applesafari8.0.0
applesafari8.0.1
applesafari8.0.2
appleitunes{"endIncluding":"12.1"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.