Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2022-02-10 — agencies required to remediate by 2022-08-10

CVE-2014-4404

HIGH

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides…

Published
Sep 18, 2014
Updated
Apr 21, 2026
Affected
0 pkgs
Patched
None yet
Exploits
3 known

EPSS Exploitation Probability

via FIRST.org ↗
62.0%probability of exploitation in next 30 days
High Risk98th percentile0.00%
61.5%61.8%62.2%62.5%62.0%62.0%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

Affected Products

3 products · 4 configurations
OS
iphone osapple
< 8.0
range
OS
mac os xapple
≥ 10.10.1 && < 10.10.3
range
OS
tvosapple
< 7.0
range
Exploits & PoCs
3

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-35440localosx✓ Verified

Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)

by Metasploit · Dec 2, 2014

Frequently Asked Questions

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
O3 Security · Impact-Aware SCA

Is CVE-2014-4404 in your stack?

O3 detects CVE-2014-4404 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.