VYPR
Unrated severityNVD Advisory· Published Sep 18, 2015· Updated May 6, 2026

CVE-2015-3801

CVE-2015-3801

Description

The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An issue in WebKit's CFNetwork Cookies allows remote attackers to bypass a single-cookie restriction in iOS before 9.

Vulnerability

The document.cookie API implementation in the CFNetwork Cookies subsystem of WebKit in Apple iOS versions prior to 9 suffers from a flaw that allows bypassing an intended single-cookie restriction. The exact mechanism is not disclosed in the available references, but it affects the cookie handling logic in the CFNetwork framework [1].

Exploitation

An attacker can exploit this vulnerability by visiting a malicious website or via unspecified vectors, requiring no authentication or user interaction beyond browsing to a crafted site. The flaw is triggered through the CFNetwork Cookies subsystem when processing cookie-related operations [1].

Impact

Successful exploitation allows a remote attacker to bypass the single-cookie restriction, potentially enabling cookie-based attacks such as session fixation or cross-site cookie manipulation, leading to information disclosure or unauthorized actions in the context of the targeted website [1].

Mitigation

Apple addressed this issue in iOS 9 as detailed in the security content update [1]. Users should update to iOS 9 or later. No workaround is documented for versions prior to iOS 9.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.