VYPR
Unrated severityNVD Advisory· Published Aug 17, 2015· Updated May 6, 2026

CVE-2015-5759

CVE-2015-5759

Description

WebKit in iOS before 8.4.1 fails to properly handle tap events, allowing a malicious website to spoof click actions and trick users into unintended actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WebKit in iOS before 8.4.1 fails to properly handle tap events, allowing a malicious website to spoof click actions and trick users into unintended actions.

Vulnerability

A spoofing vulnerability exists in the WebKit rendering engine used in Apple iOS versions prior to 8.4.1. The issue arises from improper handling of tap events when processing content from a remote website. By crafting a site that leverages these events, an attacker can make the browser interpret a user's tap as occurring at a location different from the intended target, effectively spoofing clicks on visible UI elements. The affected versions are iOS 8.4.0 and earlier across all supported devices at the time.

Exploitation

An attacker needs only to host a malicious website and lure the victim into visiting it with a vulnerable iOS browser (e.g., Safari). The attack requires no special network position or authentication; the victim's device must simply process the crafted tap event sequences delivered via the malicious site. No user interaction beyond visiting the page is required—the spoofed clicks are triggered by normal tap gestures.

Impact

Successful exploitation allows the attacker to misdirect the user's taps to arbitrary on-screen elements. This can lead to unintended actions such as activating buttons, following disguised links, or granting permissions without the user's awareness. The impact is primarily on integrity (user actions are subverted) and confidentiality (unintended actions may leak data), but does not typically lead to arbitrary code execution or system-level compromise.

Mitigation

Apple addressed this vulnerability in iOS 8.4.1, released on August 13, 2015. Users should update their devices to iOS 8.4.1 or later via the Software Update mechanism. No workarounds are available for unpatched versions [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.