CVE-2015-3762: Apple Mac OS X

Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attackers to read arbitrary files via a text file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

  • Apple Mac OS X: up to and including 10.10.4

Published 2015-08-16. Last modified 2026-06-17.