CVE-2015-1126: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 9.9% chance of exploitation in the next 30 days.

WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.

Affected products

  • Apple iPhone OS: up to and including 8.2
  • Apple Safari: up to and including 6.2.4; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …

Published 2015-04-10. Last modified 2026-06-17.