CVE-2015-3752: Apple iPhone OS
Medium severity, CVSS 5.0. EPSS: 2.8% chance of exploitation in the next 30 days.
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.
Affected products
- Apple iPhone OS: before 8.4.1 (fixed in 8.4.1)
- Apple Safari: from 6.0, before 6.2.8 (fixed in 6.2.8); from 7.0, before 7.1.8 (fixed in 7.1.8); from 8.0, before 8.0.8 (fixed in 8.0.8)
- Canonical Ubuntu Linux: version 14.04 only; version 15.10 only
Published 2015-08-16. Last modified 2026-06-17.