CVE-2012-1148: Apple Mac OS X

Medium severity, CVSS 5.0. EPSS: 3.6% chance of exploitation in the next 30 days.

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.

Affected products

  • Apple Mac OS X: up to and including 10.11.1
  • Libexpat Project Libexpat: up to and including 2.0.1; version 1.95.1 only; version 1.95.2 only; version 1.95.4 only; version 1.95.5 only; version 1.95.6 only; …

Published 2012-07-03. Last modified 2026-06-16.