CVE-2014-4457: Apple iPhone OS

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.

Affected products

  • Apple iPhone OS: up to and including 8.1; version 8.0 only; version 8.0.1 only; version 8.0.2 only

Published 2014-11-18. Last modified 2026-06-17.