CVE-2015-5825: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.

Affected products

  • Apple iPhone OS: up to and including 8.4.1
  • Apple Safari: up to and including 8.0.8

Published 2015-09-18. Last modified 2026-06-17.