First published: Sun Aug 16 2015(Updated: )
The Bluetooth subsystem in Apple OS X before 10.10.5 does not properly restrict Notification Center Service access, which allows attackers to read Notification Center notifications of certain paired devices via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-3786 is considered moderate, as it allows unauthorized access to Notification Center notifications.
To fix CVE-2015-3786, update your Apple OS X to version 10.10.5 or later.
CVE-2015-3786 affects any Apple OS X devices running version 10.10.4 or earlier.
Yes, CVE-2015-3786 can potentially be exploited remotely by crafted applications on paired devices.
CVE-2015-3786 compromises the Notification Center Service access in the Bluetooth subsystem.