PT-2015-2090 · Apple · Ios
Luyi Xing
+4
·
Published
2015-09-18
·
Updated
2016-12-22
·
CVE-2015-5835
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 9
Description
The issue is related to a lack of protection for service data in the iOS operating system. It allows a remote attacker to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack. The attack involves an unspecified URL scheme and can provide access to protected information.
Recommendations
For Apple iOS versions prior to 9, update to version 9 or later to resolve the issue. As a temporary workaround, consider restricting the installation of third-party apps to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ios