CVE-2015-5826 — Improper Access Control in Apple Iphone OS
Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 17
Description
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages4 packages
🔴Vulnerability Details
2GHSA▶
GHSA-7rq3-2jrc-rch2: WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css cont↗2022-05-17
OSV▶
CVE-2015-5826: WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css cont↗2015-09-18