ZeroHour

CVE-2016-1864

CVSS 3.0
4.3 medium
EPSS
2%p78
Published
()
Modified
Description

The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.

Vendors
apple
Products
safari, iphone os
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.