CVE-2015-1157: High severity iphone os vulnerability
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1157?
CVE-2015-1157 is classified as a denial of service vulnerability that can disrupt messaging and reboot affected devices.
Which Apple products are affected by CVE-2015-1157?
CVE-2015-1157 affects Apple iOS versions 8.0 through 8.3, as well as some versions of macOS and Apple iTunes.
How do I fix CVE-2015-1157?
To mitigate CVE-2015-1157, users should update their devices to a version of iOS that is higher than 8.3, where the issue is resolved.
What kind of attack does CVE-2015-1157 enable?
CVE-2015-1157 allows remote attackers to craft malicious Unicode text that can trigger a denial of service in notifications.
What is the impact of CVE-2015-1157 on users?
Users affected by CVE-2015-1157 may experience disruptions in messaging and unexpected reboots of their devices.