First published: Fri Sep 18 2015(Updated: )
CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5880 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive data.
To fix CVE-2015-5880, users should update their Apple iOS devices to version 9.0 or later.
CVE-2015-5880 specifically affects CoreAnimation in versions of Apple iOS prior to 9.0.
CVE-2015-5880 enables attackers to bypass IOSurface restrictions and gain access to the screen-framebuffer.
All users of Apple iOS versions before 9.0, particularly those running versions up to 8.4.1, are impacted by CVE-2015-5880.