CVE-2015-1155 describes a Same Origin Policy bypass vulnerability in WebKit, affecting Apple Safari versions prior to 6.2.6, 7.1.6, and 8.0.6, as well as Apple iPhone OS. A remote attacker could exploit this flaw via a crafted website to read arbitrary files on the victim's system. The vulnerability has a CVSS score of 4.3, indicating medium severity, with a network attack vector and medium attack complexity, potentially leading to partial confidentiality impact. While not in CISA's KEV catalog, a Metasploit module exists for exploitation, and it has garnered some community discussion and media coverage, suggesting awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 6.2.5CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:7.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:7.0.1:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:7.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.