First published: Fri Sep 18 2015(Updated: )
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=8.4.1 | |
Apple iOS and macOS | <=10.10.5 | |
Apple iOS, iPadOS, and watchOS | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5885 has been classified as a moderate severity vulnerability.
To fix CVE-2015-5885, users should update their Apple devices to the latest versions of iOS or macOS that address this vulnerability.
CVE-2015-5885 affects Apple iOS versions prior to 9, macOS Yosemite versions up to 10.10.5, and watchOS version 1.0.
CVE-2015-5885 potentially allows remote attackers to track users by exploiting cookie vulnerabilities in affected Apple products.
CVE-2015-5885 is less of a risk today if users have updated their devices to versions beyond the ones affected.