CVE-2015-7072: Apple iPhone OS

High severity, CVSS 9.3. EPSS: 2.8% chance of exploitation in the next 30 days.

dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

Affected products

  • Apple iPhone OS: up to and including 9.1
  • Apple tvOS: up to and including 9.0
  • Apple watchOS: up to and including 2.0

Published 2015-12-11. Last modified 2026-06-17.