|CVSS SCORE||6.9, (AV:L/AC:M/Au:N/C:C/I:C/A:C)|
The specific flaw exists within the IOHDIXController interface. The issue lies with the failure to validate user-supplied function addresses prior to using them. An attacker can leverage this vulnerability to escalate privileges and execute code under the context of the kernel.
Apple has issued an update to correct this vulnerability. More details can be found at:
|CREDIT||Moony Li and Jack Tang of Trend Micro