CVE-2015-5825: Apple iPhone OS
Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
Affected products
Published 2015-09-18. Last modified 2026-06-17.