Vulnerability record · CVE-2015-1130 · published 10 April 2015
CVE-2015-1130: Apple OS X Admin Framework XPC authentication bypass
Apple · Mac Os X
The XPC implementation in the Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and gain admin privileges via unspecified vectors. The flaw is a link-following issue (CWE-59) in a privileged component, so a low-privileged local account can escalate to root-level administration. It matters because it defeats the OS privilege boundary on affected Macs.
Description
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to admin with public exploit code and KEV listing, though it requires an existing local account and is fixed by a 2015 OS update.
What it is
The XPC implementation in the Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and gain admin privileges via unspecified vectors. The flaw is a link-following issue (CWE-59) in a privileged component, so a low-privileged local account can escalate to root-level administration. It matters because it defeats the OS privilege boundary on affected Macs.
Impact
An attacker with a local account gains administrative (root-equivalent) privileges on the host. That enables full control of the machine, including persistence, credential access and disabling of security controls.
Attack surface
Reached locally through the Admin Framework XPC interface; the CVSS vector AV:L/PR:L/UI:N indicates a local attacker with existing low privileges and no user interaction. No network or remote vector is described.
Exploitation
It is listed in CISA KEV (added 2022-02-10), and public exploit code is referenced (Exploit-DB 36692, SecurityFocus BID 73982), so exploitation is proven and in the wild. EPSS 30-day probability is about 9.9% (95th percentile), indicating elevated predicted activity.
What to do
- Upgrade affected Macs to OS X 10.10.3 or later per Apple's advisory (HT204659); this is the only complete fix.
- If upgrade is not immediately possible, restrict and monitor local interactive accounts and remove unnecessary admin group membership.
- Audit and minimize local user accounts and services that can reach privileged XPC/Admin Framework interfaces.
- Track KEV remediation due date (2022-08-10) and confirm all endpoints are patched or retired.
Detection
- Alert on unexpected additions to the admin group or sudoers changes on macOS hosts.
- Monitor process execution where a non-admin user context spawns privileged Admin Framework/XPC-related binaries.
- Review unified logs for authentication or authorization failures followed by successful privileged operations from the same session.
- Hunt for known public exploit artifacts or scripts associated with CVE-2015-1130 on endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1130 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Apple OS X Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1130 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1130), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.