CVE-2015-5770: Apple iPhone OS
Medium severity, CVSS 5.8. EPSS: 1.5% chance of exploitation in the next 30 days.
MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.
Affected products
- Apple iPhone OS: up to and including 8.4
Published 2015-08-17. Last modified 2026-06-17.