CVE-2015-5780: Apple Safari

High severity, CVSS 10.0. EPSS: 2.3% chance of exploitation in the next 30 days.

The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Affected products

  • Apple Safari: up to and including 8.0.8

Published 2015-10-09. Last modified 2026-06-17.