CVE-2015-5898: Apple iPhone OS

Low severity, CVSS 2.1. EPSS: 0.2% chance of exploitation in the next 30 days.

CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.

Affected products

  • Apple iPhone OS: up to and including 8.4.1
  • Apple watchOS: version 1.0 only

Published 2015-09-18. Last modified 2026-06-17.