CVE-2015-7050Sensitive Information Exposure in Apple Iphone OS

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 17

Description

WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows remote attackers to obtain sensitive browsing-history information via a crafted web site.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDapple/safari9.0.1
Appleapple/safari9.0.2
Appleapple/ios9.2
Appleapple/itunes12.3.2

🔴Vulnerability Details

2
GHSA
GHSA-pj4f-23pp-qg9c: WebKit in Apple iOS before 92022-05-17
OSV
CVE-2015-7050: WebKit in Apple iOS before 92015-12-11

📋Vendor Advisories

3
Apple
CVE-2015-7050: iOS 9.2
Apple
CVE-2015-7050: iTunes 12.3.2
Apple
CVE-2015-7050: Safari 9.0.2
CVE-2015-7050 — Sensitive Information Exposure in Apple | cvebase