First published: Fri Oct 09 2015(Updated: )
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | <=8.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5780 is considered to have unspecified impact, which could lead to potential security risks due to unauthorized extension replacement.
To fix CVE-2015-5780, users should upgrade to Apple Safari version 9 or later.
CVE-2015-5780 affects Apple Safari versions prior to 9.0, specifically up to version 8.0.8.
Using vulnerable versions of Safari exposes users to potential unauthorized modifications of installed extensions.
No, affected versions of Safari do not require user confirmation before replacing an installed extension.