CVE-2015-3759Link Following in Apple Iphone OS

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 83.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 17

Description

Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

Appleapple/ios8.4.1
Appleapple/apple_tv7.2.1

🔴Vulnerability Details

1
GHSA
GHSA-r3cx-42vx-5v5p: Location Framework in Apple iOS before 82022-05-17

📋Vendor Advisories

2
Apple
CVE-2015-3759: iOS 8.4.1
Apple
CVE-2015-3759: Apple TV 7.2.1
CVE-2015-3759 — Link Following in Apple Iphone OS | cvebase