CVE-2015-3752 describes a vulnerability in the Content Security Policy (CSP) implementation of WebKit in Apple Safari and iOS, affecting versions prior to 6.2.8, 7.1.8, and 8.0.8, and iOS before 8.4.1. This flaw allows remote attackers to bypass CSP restrictions and obtain sensitive information, specifically cookies, through cross-origin or private-browsing report requests. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having low attack complexity, leading to a partial confidentiality impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, < 6.2.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 7.0, < 7.1.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.0.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 8.4.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.