logo

New Crucial Vulnerabilities in Apple's bluetoothd daemon

ID: 62c7dd7e-26e5-5077-9a77-c20205f11e2d

STIX ID: report--62c7dd7e-26e5-5077-9a77-c20205f11e2d

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2018-01-29

Date Updated: 2026-05-01

...
...

Zimperium zLabs discovered two critical CoreBluetooth vulnerabilities in the bluetoothd daemon (CVE-2018-4087 and CVE-2018-4095) that allow stack-based memory corruption and arbitrary code execution across many system daemons on iOS, tvOS and watchOS, effectively enabling sandbox escapes and privilege escalation; Apple released patches in iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 and a detailed technical write-up and exploit code are promised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.