CVE-2014-4480: Apple iPhone OS

High severity, CVSS 10.0. EPSS: 2.8% chance of exploitation in the next 30 days.

Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Affected products

  • Apple iPhone OS: up to and including 8.1.2
  • Apple tvOS: up to and including 7.0.1

Published 2015-01-30. Last modified 2026-06-17.