CVE-2015-5790
Description
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WebKit memory corruption in Apple iOS before 9 and iTunes before 12.3 allows remote code execution or denial of service via a crafted website.
Vulnerability
CVE-2015-5790 is a memory corruption vulnerability in WebKit, the browser engine used in Apple iOS prior to version 9 and iTunes prior to version 12.3 [1][3]. The bug can be triggered by visiting a maliciously crafted website, leading to memory corruption and application crash. No specific configuration or special conditions are required; simply loading the page in the affected WebKit instance is sufficient.
Exploitation
An attacker needs only to host a crafted website and entice the user to visit it. No authentication or prior access is required. Upon loading the malicious page, the WebKit engine processes the content in a way that causes memory corruption. The precise mechanism is not disclosed, but the result is exploitable memory corruption.
Impact
Successful exploitation allows an attacker to execute arbitrary code on the affected device, potentially gaining full control, or cause a denial of service via application crash. The compromise occurs at the privilege level of the WebKit process, which can lead to further escalation if combined with other vulnerabilities.
Mitigation
Apple addressed this vulnerability in iOS 9 [1] and iTunes 12.3 [3]. Users should update to these versions or later. No workarounds are available for earlier versions. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*range: <=12.2
- (no CPE)range: <12.3
- Range: <9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlnvdVendor Advisory
- lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlnvdVendor Advisory
- lists.apple.com/archives/security-announce/2015/Sep/msg00007.htmlnvdVendor Advisory
- support.apple.com/HT205212nvdVendor Advisory
- support.apple.com/HT205221nvdVendor Advisory
- support.apple.com/HT205265nvdVendor Advisory
- www.securityfocus.com/bid/76763nvd
- www.securitytracker.com/id/1033609nvd
News mentions
0No linked articles in our index yet.