← Vulnerability feed

Vulnerability record · CVE-2015-1130 · published 10 April 2015

CVE-2015-1130: Apple OS X Admin Framework XPC authentication bypass

Apple · Mac Os X

The XPC implementation in the Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and gain admin privileges via unspecified vectors. The flaw is a link-following issue (CWE-59) in a privileged component, so a low-privileged local account can escalate to root-level administration. It matters because it defeats the OS privilege boundary on affected Macs.

7.8 CVSS 3.1 High CISA KEV since 10 Feb 2022 EPSS 9.9% · top 4.6% CWE-59 · Link following
7.8CVSS 3.1 base score, v2 7.2
9.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityLocal privilege escalation to admin with public exploit code and KEV listing, though it requires an existing local account and is fixed by a 2015 OS update.

What it is

The XPC implementation in the Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and gain admin privileges via unspecified vectors. The flaw is a link-following issue (CWE-59) in a privileged component, so a low-privileged local account can escalate to root-level administration. It matters because it defeats the OS privilege boundary on affected Macs.

Impact

An attacker with a local account gains administrative (root-equivalent) privileges on the host. That enables full control of the machine, including persistence, credential access and disabling of security controls.

Attack surface

Reached locally through the Admin Framework XPC interface; the CVSS vector AV:L/PR:L/UI:N indicates a local attacker with existing low privileges and no user interaction. No network or remote vector is described.

Exploitation

It is listed in CISA KEV (added 2022-02-10), and public exploit code is referenced (Exploit-DB 36692, SecurityFocus BID 73982), so exploitation is proven and in the wild. EPSS 30-day probability is about 9.9% (95th percentile), indicating elevated predicted activity.

What to do

  • Upgrade affected Macs to OS X 10.10.3 or later per Apple's advisory (HT204659); this is the only complete fix.
  • If upgrade is not immediately possible, restrict and monitor local interactive accounts and remove unnecessary admin group membership.
  • Audit and minimize local user accounts and services that can reach privileged XPC/Admin Framework interfaces.
  • Track KEV remediation due date (2022-08-10) and confirm all endpoints are patched or retired.

Detection

  • Alert on unexpected additions to the admin group or sudoers changes on macOS hosts.
  • Monitor process execution where a non-admin user context spawns privileged Admin Framework/XPC-related binaries.
  • Review unified logs for authentication or authorization failures followed by successful privileged operations from the same session.
  • Hunt for known public exploit artifacts or scripts associated with CVE-2015-1130 on endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-1130 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Apple OS X Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html Broken LinkMailing ListVendor Advisory
http://www.osvdb.org/120418 Broken Link
http://www.securityfocus.com/bid/73982 Broken LinkExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032048 Broken LinkThird Party AdvisoryVDB Entry
https://support.apple.com/HT204659 Vendor Advisory
https://www.exploit-db.com/exploits/36692/ ExploitThird Party AdvisoryVDB Entry
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html Broken LinkMailing ListVendor Advisory
http://www.osvdb.org/120418 Broken Link
http://www.securityfocus.com/bid/73982 Broken LinkExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1032048 Broken LinkThird Party AdvisoryVDB Entry
https://support.apple.com/HT204659 Vendor Advisory
https://www.exploit-db.com/exploits/36692/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1130 US Government Resource

Track CVE-2015-1130 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed8.8CVE-2021-1789Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Process…KEVEPSS 14%analysed7.8CVE-2021-30713Apple macOS privacy preference bypass via missing authorizationmacOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferen…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2015-1130), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.