CVE-2015-3725 describes a denial-of-service vulnerability in Apple iOS before version 8.4, specifically within the MobileInstallation component. Attackers could exploit this by crafting a universal provisioning profile app that creates non-unique Watch bundle IDs, leading to an ID collision and preventing Watch apps from launching. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial availability impact, though it does not affect confidentiality or integrity. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, despite one article mentioning it in relation to the "Masque" flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.