CVE-2015-5832: Apple iPhone OS

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.

Affected products

  • Apple iPhone OS: up to and including 8.4.1

Published 2015-09-18. Last modified 2026-06-17.