CVE-2015-3725 — Apple Iphone OS vulnerability

CWE-3993 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMay 17

Description

MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

â–¶NVDapple/iphone_os8.3
â–¶Appleapple/ios8.4

🔴Vulnerability Details

1
GHSA
GHSA-ff32-6745-wcvq: MobileInstallation in Apple iOS before 8↗2022-05-17
â–¶

📋Vendor Advisories

1
Apple
CVE-2015-3725: iOS 8.4↗
â–¶
CVE-2015-3725 — Apple Iphone OS vulnerability | cvebase