First published: Fri Sep 18 2015(Updated: )
PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | =1.0 | |
iStyle @cosme iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5837 is classified as a critical vulnerability due to its potential to allow the installation of unverified extensions.
To mitigate CVE-2015-5837, update affected Apple iOS devices to version 9.0 or later, as this version addresses the vulnerability.
CVE-2015-5837 affects Apple iOS devices running versions up to 8.4.1 and watchOS 1.0.
The impact of CVE-2015-5837 includes the ability for unauthorized applications to install arbitrary app extensions, potentially compromising device security.
CVE-2015-5837 can be exploited by attackers with the capability to distribute crafted enterprise applications to targeted devices.