Unrated severityNVD Advisory· Published Nov 22, 2015· Updated May 6, 2026
CVE-2015-5859
CVE-2015-5859
Description
The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/HT205212nvdVendor Advisory
- support.apple.com/HT205267nvd
News mentions
0No linked articles in our index yet.