CVE-2015-3758: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL.

Affected products

  • Apple iPhone OS: up to and including 8.4

Published 2015-08-16. Last modified 2026-06-17.