First published: Fri Jul 03 2015(Updated: )
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3688, and CVE-2015-3689.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.3 | |
Apple iTunes | <=12.2 | |
macOS Yosemite | <=10.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3687 is considered critical due to its potential to allow remote code execution and denial of service.
To fix CVE-2015-3687, update your iOS device to version 8.4 or later, and update macOS to version 10.10.4 or later.
CVE-2015-3687 affects Apple iOS versions up to 8.3, Apple iTunes versions up to 12.2, and macOS Yosemite versions up to 10.10.3.
CVE-2015-3687 can be exploited through crafted text files which may lead to remote code execution or memory corruption.
If updating is not possible, avoid opening untrusted text files and disable applications that process text to mitigate CVE-2015-3687.