First published: Fri Sep 18 2015(Updated: )
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=8.0.8 | |
iStyle @cosme iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5825 is categorized as a medium severity vulnerability.
To fix CVE-2015-5825, update your Apple Safari or iPhone OS to version 9 or higher.
CVE-2015-5825 exploits improper restrictions in the Performance API, allowing attackers to access sensitive user data.
CVE-2015-5825 affects Apple Safari versions up to 8.0.8 and Apple iPhone OS versions up to 8.4.1.
Yes, CVE-2015-5825 can potentially lead to data leaks of browser history and network traffic.