CVE-2014-4459: Apple iPhone OS
Medium severity, CVSS 6.8. EPSS: 4.6% chance of exploitation in the next 30 days.
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
Affected products
- Apple iPhone OS: before 8.1.3 (fixed in 8.1.3)
- Apple iTunes: before 12.2 (fixed in 12.2)
- Apple Mac OS X: before 10.10.1 (fixed in 10.10.1)
- Apple Safari: from 6.0, before 6.2.1 (fixed in 6.2.1); from 7.0, before 7.1.1 (fixed in 7.1.1); from 8.0, before 8.0.1 (fixed in 8.0.1)
- Apple tvOS: before 7.0.3 (fixed in 7.0.3)
Published 2014-11-18. Last modified 2026-06-17.