Release appearance
iOS 4.3.4 Public
Recorded context
About this appearance
iOS 4.3.4 closed two crafted-PDF font vulnerabilities and a framebuffer privilege-escalation path.
- Date
- Jul 15, 2011
- Availability
- available
- Revision
- No
Release notes
What changed
Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.
Two CoreGraphics corrections addressed FreeType handling of TrueType and Type 1 fonts inside malicious PDF files. Apple documented application termination or arbitrary code execution as possible outcomes.[1]
Source ledger
References
Sources are linked to the claims they support. Publication and access dates are shown when available.
- About the security content of iOS 4.3.4 Software Update
Apple Support · 2026-07-30 · CoreGraphics — CVE-2010-3855 and CVE-2011-0226
- About the security content of iOS 4.3.4 Software Update
Apple Support · 2026-07-30 · IOMobileFrameBuffer — CVE-2011-0227
- Apple security updates (2011 to 2012)
Apple Support · Apple · 2023-08-10T00:00:00.000Z · iOS 4.3.4 — 15 July 2011
- About the security content of iOS 4.3.4 Software Update
Apple Support · 2026-07-30 · CoreGraphics — CVE-2010-3855
- About the security content of iOS 4.3.4 Software Update
Apple Support · 2026-07-30 · CoreGraphics — CVE-2011-0226
- About the security content of iOS 4.3.4 Software Update
Apple Support · 2026-07-30 · iOS 4.3.4 security content
Release changes
Changed in this release
Features, fixes, removals, and regressions first observed in this release record.
security · fixed
IOMobileFrameBuffer privilege boundary
The defect could allow malicious code already running as the user to gain system privileges.
- [1] About the security content of iOS 4.3.4 Software Update · IOMobileFrameBuffer — CVE-2011-0227
security · fixed
Type 1 PDF font signedness
Apple documented unexpected termination or arbitrary code execution from a malicious PDF.
- [1] About the security content of iOS 4.3.4 Software Update · CoreGraphics — CVE-2011-0226
security · fixed
TrueType PDF font overflow
Opening a malicious PDF could otherwise terminate an application or execute arbitrary code.
- [1] About the security content of iOS 4.3.4 Software Update · CoreGraphics — CVE-2010-3855