First published: Fri Apr 10 2015(Updated: )
WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=7.1 | |
iStyle @cosme iPhone OS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1123 has a high severity rating due to its potential to allow remote code execution.
To mitigate CVE-2015-1123, update your Apple iOS device to version 8.3 or later, or Apple TV to version 7.2 or later.
CVE-2015-1123 affects Apple iOS versions prior to 8.3 and Apple TV versions before 7.2.
Exploitation of CVE-2015-1123 can lead to arbitrary code execution and potential denial of service through memory corruption.
Disabling or avoiding the use of vulnerable web features can minimize the risk of exploitation related to CVE-2015-1123.