CVE-2015-1063 is a denial-of-service vulnerability affecting Apple iOS before version 8.2, specifically within the CoreTelephony component. A remote attacker can trigger a NULL pointer dereference and device restart by sending a specially crafted Class 0 SMS message. This vulnerability has a CVSS score of 7.8, indicating high severity due to its network-based attack vector, low complexity, and complete availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, though it is not on the CISA KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.1.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.