CVE-2015-3750: Apple iPhone OS

Medium severity, CVSS 6.4. EPSS: 1.9% chance of exploitation in the next 30 days.

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

Affected products

  • Apple iPhone OS: up to and including 8.4; before 8.4.1 (fixed in 8.4.1)
  • Apple Safari: from 6.0, before 6.2.8 (fixed in 6.2.8); from 7.0, before 7.1.8 (fixed in 7.1.8); from 8.0, before 8.0.8 (fixed in 8.0.8)

Published 2015-08-16. Last modified 2026-06-17.