CVE-2015-3659: Apple iPhone OS

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

Affected products

  • Apple iPhone OS: up to and including 8.3
  • Apple Mac OS X: up to and including 10.10.3
  • Apple Safari: up to and including 6.2.6; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …

Published 2015-07-03. Last modified 2026-06-17.