CVE-2012-3749: Apple iPhone OS

Medium severity, CVSS 5.0. EPSS: 2.2% chance of exploitation in the next 30 days.

The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.

Affected products

  • Apple iPhone OS: up to and including 6.0; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …

Published 2012-11-03. Last modified 2026-06-16.