First published: Fri Sep 18 2015(Updated: )
NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sensitive memory-layout information via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.5 | |
iStyle @cosme iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5831 has been assigned a high severity rating due to its potential to expose sensitive information.
To address CVE-2015-5831, users should upgrade to the latest version of iOS or macOS that contains the security patch.
CVE-2015-5831 allows attackers to obtain sensitive memory-layout information via a specially crafted application.
CVE-2015-5831 affects all iOS versions prior to 9, specifically up to 8.4.1.
Yes, macOS versions up to 10.10.5 are also vulnerable to CVE-2015-5831.