First published: Fri Sep 18 2015(Updated: )
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=8.4.1 | |
Apple Mobile Safari | <=8.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5788 has been classified as a high severity vulnerability due to its potential to bypass the Same Origin Policy.
CVE-2015-5788 allows remote attackers to access sensitive image information, compromising user privacy.
CVE-2015-5788 affects Apple iOS versions up to 8.4.1 and Safari versions up to 8.0.8.
To mitigate CVE-2015-5788, users should update their iOS or Safari versions to the latest available releases.
CVE-2015-5788 is considered a notable vulnerability within the WebKit engine, being specifically related to canvas elements.