CVE-2015-5858: Infoleak
Published Sep 18, 2015
·Updated
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.
Affected Software
2 affected components
Apple iPhone OS<=8.4.1
Apple WatchOS=1.0
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5858?
CVE-2015-5858 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-5858?
To mitigate CVE-2015-5858, users should update their Apple devices to iOS version 9 or later.
3
What type of attacks does CVE-2015-5858 allow?
CVE-2015-5858 allows remote attackers to bypass HSTS protection, potentially exposing sensitive information.
4
Which Apple devices are affected by CVE-2015-5858?
CVE-2015-5858 affects Apple iOS devices before version 9 and Apple watchOS version 1.0.
5
What is the main risk associated with CVE-2015-5858?
The main risk of CVE-2015-5858 is the exposure of sensitive information due to improper URL handling.