CVE-2015-1084: Apple iPhone OS
Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.
The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
Affected products
- Apple iPhone OS: up to and including 8.2
- Apple Safari: up to and including 6.2.3; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
Published 2015-03-18. Last modified 2026-06-17.