CVE-2015-5837: Input Validation
PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5837?
CVE-2015-5837 is classified as a critical vulnerability due to its potential to allow the installation of unverified extensions.
How do I fix CVE-2015-5837?
To mitigate CVE-2015-5837, update affected Apple iOS devices to version 9.0 or later, as this version addresses the vulnerability.
What types of devices are affected by CVE-2015-5837?
CVE-2015-5837 affects Apple iOS devices running versions up to 8.4.1 and watchOS 1.0.
What is the impact of CVE-2015-5837?
The impact of CVE-2015-5837 includes the ability for unauthorized applications to install arbitrary app extensions, potentially compromising device security.
Who can exploit CVE-2015-5837?
CVE-2015-5837 can be exploited by attackers with the capability to distribute crafted enterprise applications to targeted devices.