PT-2015-1877 · Apple · Uikit Webview+2

Brian Simmons

+1

·

Published

2015-08-16

·

Updated

2016-12-24

·

CVE-2015-3758

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 8.4.1
Description The issue exists due to insufficient input validation in the UIKit WebView component of the iOS operating system. This allows a remote attacker to initiate arbitrary FaceTime calls using a specially crafted URL, bypassing the intended user-confirmation requirement.
Recommendations For iOS versions prior to 8.4.1, update to version 8.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to FaceTime or avoiding the use of specially crafted URLs in the affected UIKit WebView component until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11223
CVE-2015-3758

Affected Products

Facetime
Uikit Webview
Ios