CVE-2015-5839: Medium severity apple ios, ipados, and watchos vulnerability
Published Sep 18, 2015
·Updated
dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.
Affected Software
3 affected components
Apple WatchOS=1.0
Apple iOS and macOS<=10.10.5
Apple iPhone OS<=8.4.1
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5839?
CVE-2015-5839 has a high severity rating due to its potential to allow code-signing bypass, leading to execution of malicious code.
2
How do I fix CVE-2015-5839?
To fix CVE-2015-5839, update your affected Apple iOS or macOS software to the latest versions that mitigate this vulnerability.
3
Which versions of Apple software are affected by CVE-2015-5839?
CVE-2015-5839 affects Apple iOS versions prior to 9, macOS Yosemite up to 10.10.5, and watchOS 1.0.
4
What is the impact of exploiting CVE-2015-5839?
Exploiting CVE-2015-5839 could allow attackers to execute arbitrary code without proper code-signing validation.
5
Is there a workaround for CVE-2015-5839?
There are no effective workarounds for CVE-2015-5839; updating to the latest software version is recommended.