CVE-2015-5825

WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-09-18 10:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-5825

Mitre link : CVE-2015-5825

CVE.ORG link : CVE-2015-5825


JSON object : View

Products Affected

apple

  • safari
  • iphone_os
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor