CVE-2015-7016: Apple Mac OS X

High severity, CVSS 7.6. EPSS: 1.4% chance of exploitation in the next 30 days.

The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted developer-signed app.

Affected products

  • Apple Mac OS X: up to and including 10.11.0

Published 2015-10-23. Last modified 2026-06-17.