CVE-2015-3756: Apple iPhone OS
Low severity, CVSS 2.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Certificate UI in Apple iOS before 8.4.1 does not prevent X.509 certificate acceptance within the lock screen, which allows physically proximate attackers to establish arbitrary certificate trust relationships by completing a dialog.
Affected products
- Apple iPhone OS: up to and including 8.4
Published 2015-08-16. Last modified 2026-06-17.