CVE-2015-5885: Infoleak
Published Sep 18, 2015
·Updated
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
Affected Software
3 affected components
Apple iPhone OS<=8.4.1
Apple iOS and macOS<=10.10.5
Apple WatchOS=1.0
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5885?
CVE-2015-5885 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-5885?
To fix CVE-2015-5885, users should update their Apple devices to the latest versions of iOS or macOS that address this vulnerability.
3
What systems are affected by CVE-2015-5885?
CVE-2015-5885 affects Apple iOS versions prior to 9, macOS Yosemite versions up to 10.10.5, and watchOS version 1.0.
4
What impact does CVE-2015-5885 have on user privacy?
CVE-2015-5885 potentially allows remote attackers to track users by exploiting cookie vulnerabilities in affected Apple products.
5
Is CVE-2015-5885 still a risk for users today?
CVE-2015-5885 is less of a risk today if users have updated their devices to versions beyond the ones affected.