CVE-2015-1157: Apple iPhone OS

High severity, CVSS 7.8. EPSS: 5.6% chance of exploitation in the next 30 days.

CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.

Affected products

  • Apple iPhone OS: version 8.0 only; version 8.0.1 only; version 8.0.2 only; version 8.1 only; version 8.1.2 only; version 8.1.3 only; …
  • Apple iTunes: up to and including 12.2
  • Apple Mac OS X: up to and including 10.0.3

Published 2015-05-28. Last modified 2026-06-17.