CVE-2015-1130: Apple OS X Authentication Bypass Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 9.9% chance of exploitation in the next 30 days.

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

Affected products

  • Apple Mac OS X: before 10.10.3 (fixed in 10.10.3)

Published 2015-04-10. Last modified 2026-06-17.