CVE-2015-3658: Apple iPhone OS

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site.

Affected products

  • Apple iPhone OS: up to and including 8.3
  • Apple Mac OS X: up to and including 10.10.3
  • Apple Safari: up to and including 6.2.6; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …

Published 2015-07-03. Last modified 2026-06-17.