First published: Fri Apr 10 2015(Updated: )
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes | <=12.1 | |
tvOS | <=7.1 | |
Apple iPhone OS | <=8.2 | |
Apple Safari | <=6.2.4 | |
Apple Safari | =7.0 | |
Apple Safari | =7.0.1 | |
Apple Safari | =7.0.2 | |
Apple Safari | =7.0.3 | |
Apple Safari | =7.0.4 | |
Apple Safari | =7.0.5 | |
Apple Safari | =7.0.6 | |
Apple Safari | =7.1.0 | |
Apple Safari | =7.1.1 | |
Apple Safari | =7.1.2 | |
Apple Safari | =7.1.3 | |
Apple Safari | =7.1.4 | |
Apple Safari | =8.0.0 | |
Apple Safari | =8.0.1 | |
Apple Safari | =8.0.2 | |
Apple Safari | =8.0.3 | |
Apple Safari | =8.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1124 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2015-1124, update to the latest version of affected software, including iOS 8.3 or later, Safari 8.0.5 or later, and relevant updates for Apple TV.
CVE-2015-1124 can be exploited to execute arbitrary code or cause a denial of service due to memory corruption.
CVE-2015-1124 affects Apple iTunes prior to 12.1, Apple iOS before 8.3, tvOS before 7.1, and multiple versions of Safari.
If you cannot update, consider using alternative browsers or limiting your device's exposure to untrusted websites to reduce the risk associated with CVE-2015-1124.