CVE-2014-1314: Apple Mac OS X

High severity, CVSS 10.0. EPSS: 3.1% chance of exploitation in the next 30 days.

WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.

Affected products

  • Apple Mac OS X: up to and including 10.9.2; version 10.9 only; version 10.9.1 only; version 10.8.0 only; version 10.8.1 only; version 10.8.2 only; …

Published 2014-04-23. Last modified 2026-06-17.