CVE-2014-4452: Apple iPhone OS
Medium severity, CVSS 5.4. EPSS: 1.3% chance of exploitation in the next 30 days.
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.
Affected products
- Apple iPhone OS: from 8.0, before 8.1.1 (fixed in 8.1.1)
- Apple iTunes: before 12.2 (fixed in 12.2)
- Apple Safari: from 6.0, before 6.2.1 (fixed in 6.2.1); from 7.0, before 7.1.1 (fixed in 7.1.1); from 8.0, before 8.0.1 (fixed in 8.0.1)
- Apple tvOS: from 6.0, before 7.0.2 (fixed in 7.0.2)
Published 2014-11-18. Last modified 2026-06-17.