CVE-2014-3187: Apple iPhone OS
Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site.
Affected products
- Apple iPhone OS: affected versions not specified
- Google Chrome: up to and including 37.0.2062.59; version 37.0.2062.0 only; version 37.0.2062.1 only; version 37.0.2062.2 only; version 37.0.2062.3 only; version 37.0.2062.4 only; …
Published 2014-10-08. Last modified 2026-06-17.