CVE-2014-1381: Apple Mac OS X

High severity, CVSS 10.0. EPSS: 2.9% chance of exploitation in the next 30 days.

Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted call.

Affected products

  • Apple Mac OS X: version 10.9 only; version 10.9.1 only; version 10.9.2 only; version 10.9.3 only

Published 2014-07-01. Last modified 2026-06-17.