First published: Sun Aug 16 2015(Updated: )
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | >=6.0<6.2.8 | |
Apple Mobile Safari | >=7.0<7.1.8 | |
Apple Mobile Safari | >=8.0<8.0.8 | |
iStyle @cosme iPhone OS | <8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3755 has been assigned a high severity rating due to its potential for user interface spoofing.
To address CVE-2015-3755, update your version of Apple Safari to 6.2.8, 7.1.8, or 8.0.8, or upgrade to a later version.
CVE-2015-3755 affects Apple Safari versions before 6.2.8, 7.1.8, and 8.0.8, as well as iOS versions prior to 8.4.1.
CVE-2015-3755 allows remote attackers to spoof the user interface via a malformed URL.
There is no official workaround for CVE-2015-3755; the recommended solution is to apply the security updates.