First published: Thu May 28 2015(Updated: )
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | =8.0 | |
Apple iPhone OS | =8.0.1 | |
Apple iPhone OS | =8.0.2 | |
Apple iPhone OS | =8.1 | |
Apple iPhone OS | =8.1.2 | |
Apple iPhone OS | =8.1.3 | |
Apple iPhone OS | =8.2 | |
Apple iPhone OS | =8.3 | |
macOS Yosemite | <=10.0.3 | |
Apple iTunes | <=12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1157 is classified as a denial of service vulnerability that can disrupt messaging and reboot affected devices.
CVE-2015-1157 affects Apple iOS versions 8.0 through 8.3, as well as some versions of macOS and Apple iTunes.
To mitigate CVE-2015-1157, users should update their devices to a version of iOS that is higher than 8.3, where the issue is resolved.
CVE-2015-1157 allows remote attackers to craft malicious Unicode text that can trigger a denial of service in notifications.
Users affected by CVE-2015-1157 may experience disruptions in messaging and unexpected reboots of their devices.