CVE-2015-8659: Apple iPhone OS

Critical severity, CVSS 10.0. EPSS: 4% chance of exploitation in the next 30 days.

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

Affected products

  • Apple iPhone OS: up to and including 9.2.1
  • Apple Mac OS X: up to and including 10.11.3
  • Apple tvOS: up to and including 9.1
  • Apple watchOS: up to and including 2.1
  • NGHTTP2 NGHTTP2: up to and including 1.5.0

Published 2016-01-12. Last modified 2026-06-17.