CVE-2015-1086: Apple iPhone OS

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

Affected products

  • Apple iPhone OS: up to and including 8.2
  • Apple tvOS: up to and including 7.1

Published 2015-04-10. Last modified 2026-06-17.