Apple iOS is prone to an underflow condition. The system fails to properly sanitize user-supplied input resulting in an integer underflow. With a specially crafted catalog file in an HFS disk image, a local attacker can potentially cause arbitrary code execution.