CVE-2015-7050: Infoleak
Published Dec 11, 2015
·Updated
WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows remote attackers to obtain sensitive browsing-history information via a crafted web site.
Affected Software
2 affected components
iPhone OS<=9.1
Safari<=9.0.1
Event History
Dec 11, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7050?
CVE-2015-7050 has a medium severity rating due to its potential to expose sensitive browsing history information.
2
How do I fix CVE-2015-7050?
To fix CVE-2015-7050, update your Apple iOS device to version 9.2 or later and Safari to version 9.0.2 or later.
3
What systems are affected by CVE-2015-7050?
CVE-2015-7050 affects Apple iPhone OS versions up to 9.1 and Safari versions up to 9.0.1.
4
What type of attack does CVE-2015-7050 facilitate?
CVE-2015-7050 facilitates an attack that allows remote attackers to gain access to sensitive browsing history information.
5
Is there a workaround for CVE-2015-7050?
There is no specific workaround for CVE-2015-7050; the recommended action is to apply the necessary updates.