VYPR
Unrated severityNVD Advisory· Published Jul 3, 2015· Updated May 6, 2026

CVE-2015-3722

CVE-2015-3722

Description

In iOS before 8.4, the App Store failed to enforce unique bundle IDs, allowing a crafted provisioning profile app to cause launch outages via ID collision.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In iOS before 8.4, the App Store failed to enforce unique bundle IDs, allowing a crafted provisioning profile app to cause launch outages via ID collision.

Vulnerability

In Apple iOS prior to version 8.4, the Application Store install logic for universal provisioning profile apps did not verify that a new app's bundle ID was unique. An attacker could exploit this by crafting a malicious app that uses a bundle ID already associated with a legitimate app, causing a collision. The issue affected iPhone 4s and later, iPod touch (5th generation) and later, and iPad 2 and later [1].

Exploitation

An attacker creates a universal provisioning profile app that declares an existing bundle ID. The victim must install this malicious app, likely through a distribution channel that accepts such profiles (e.g., enterprise deployment). No additional authentication or network position beyond delivering the app is required. Once installed, the app triggers a bundle ID collision with the installed legitimate app [1].

Impact

Successful exploitation results in a denial of service: the legitimate app associated with the colliding bundle ID becomes unable to launch. No data theft, privilege escalation, or code execution is reported. The attacker gains the ability to interfere with app availability on the device [1].

Mitigation

Apple addressed this issue in iOS 8.4, released on June 30, 2015, by introducing improved collision checking for bundle IDs. Users should update to iOS 8.4 or later to receive the fix. No workarounds are documented for unpatched versions [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.