CVE-2014-4404: Apple OS X Heap-Based Buffer Overflow Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 48.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

Affected products

  • Apple iPhone OS: before 8.0 (fixed in 8.0)
  • Apple Mac OS X: before 10.10.0 (fixed in 10.10.0); from 10.10.1, before 10.10.3 (fixed in 10.10.3)
  • Apple tvOS: before 7.0 (fixed in 7.0)

Published 2014-09-18. Last modified 2026-06-17.