CVE-2014-8840: Apple iPhone OS

Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.

The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirection of an SSL URL to the iTunes Store.

Affected products

  • Apple iPhone OS: up to and including 8.1.2

Published 2015-01-30. Last modified 2026-06-17.