CVE-2014-8840: Apple iPhone OS
Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.
The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirection of an SSL URL to the iTunes Store.
Affected products
- Apple iPhone OS: up to and including 8.1.2
Published 2015-01-30. Last modified 2026-06-17.