CVE-2015-1109: Apple iPhone OS

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.

Affected products

  • Apple iPhone OS: up to and including 8.2

Published 2015-04-10. Last modified 2026-06-17.