{"api_version":"1","generated_at":"2026-07-23T03:39:33+00:00","cve":"CVE-2015-3752","urls":{"html":"https://cve.report/CVE-2015-3752","api":"https://cve.report/api/cve/CVE-2015-3752.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3752","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3752"},"summary":{"title":"CVE-2015-3752","description":"The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.","state":"PUBLISHED","assigner":"apple","published_at":"2015-08-16 23:59:25","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id/1033274","name":"http://www.securitytracker.com/id/1033274","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari Flaws Let Remote Users Bypass Security Controls, Obtain Potentially Sensitive Information, Spoof Interfaces and URLS, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2937-1","name":"http://www.ubuntu.com/usn/USN-2937-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2937-1: WebKitGTK+ vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT205033","name":"https://support.apple.com/kb/HT205033","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76341","name":"http://www.securityfocus.com/bid/76341","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"WebKit Same Origin Policy Multiple Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html","name":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2016:0915-1: moderate: Security update for webkitgtk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT205030","name":"https://support.apple.com/kb/HT205030","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 8.4.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2015-08-13-3 iOS 8.4.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2015-08-13-1 Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3752","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3752","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:56:14.814Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1033274","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033274"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT205030"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2016:0915","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html"},{"name":"76341","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76341"},{"name":"APPLE-SA-2015-08-13-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT205033"},{"name":"USN-2937-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2937-1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-22T18:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"1033274","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033274"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT205030"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2016:0915","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html"},{"name":"76341","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76341"},{"name":"APPLE-SA-2015-08-13-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT205033"},{"name":"USN-2937-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2937-1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2015-3752","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1033274","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033274"},{"name":"https://support.apple.com/kb/HT205030","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT205030"},{"name":"APPLE-SA-2015-08-13-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2016:0915","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html"},{"name":"76341","refsource":"BID","url":"http://www.securityfocus.com/bid/76341"},{"name":"APPLE-SA-2015-08-13-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html"},{"name":"https://support.apple.com/kb/HT205033","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT205033"},{"name":"USN-2937-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2937-1"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2015-3752","datePublished":"2015-08-16T23:00:00.000Z","dateReserved":"2015-05-07T00:00:00.000Z","dateUpdated":"2024-08-06T05:56:14.814Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-16 23:59:25","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.2.8","matchCriteriaId":"47782F4A-23C6-4F74-B4D1-DE59356AA9AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.1.8","matchCriteriaId":"2532A5EF-F419-4D51-BFB0-70AA3269691B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"8.0.8","matchCriteriaId":"D5A5B82D-B522-4F3F-B46B-DA1317F75C60"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"8.4.1","matchCriteriaId":"F597127C-D985-43BC-AE13-8E076B270CC4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","matchCriteriaId":"B5A6F2F3-4894-4392-8296-3B8DD2679084"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*","matchCriteriaId":"E88A537F-F4D0-46B9-9E37-965233C2A355"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3752","Ordinal":"1","Title":"CVE-2015-3752","CVE":"CVE-2015-3752","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3752","Ordinal":"1","NoteData":"The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.","Type":"Description","Title":"CVE-2015-3752"},{"CveYear":"2015","CveId":"3752","Ordinal":"2","NoteData":"2015-08-16","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3752","Ordinal":"3","NoteData":"2016-12-22","Type":"Other","Title":"Modified"}]}}}