CVE-2014-1381: Apple Mac OS X
High severity, CVSS 10.0. EPSS: 2.9% chance of exploitation in the next 30 days.
Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted call.
Affected products
- Apple Mac OS X: version 10.9 only; version 10.9.1 only; version 10.9.2 only; version 10.9.3 only
Published 2014-07-01. Last modified 2026-06-17.