CVE-2014-4459: Apple iPhone OS

Medium severity, CVSS 6.8. EPSS: 4.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.

Affected products

  • Apple iPhone OS: before 8.1.3 (fixed in 8.1.3)
  • Apple iTunes: before 12.2 (fixed in 12.2)
  • Apple Mac OS X: before 10.10.1 (fixed in 10.10.1)
  • Apple Safari: from 6.0, before 6.2.1 (fixed in 6.2.1); from 7.0, before 7.1.1 (fixed in 7.1.1); from 8.0, before 8.0.1 (fixed in 8.0.1)
  • Apple tvOS: before 7.0.3 (fixed in 7.0.3)

Published 2014-11-18. Last modified 2026-06-17.