CVE-2015-5907: Apple iPhone OS

Low severity, CVSS 2.6. EPSS: 0.8% chance of exploitation in the next 30 days.

WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.

Affected products

  • Apple iPhone OS: up to and including 8.4.1

Published 2015-09-18. Last modified 2026-06-17.