Palo Alto Networks Researchers Discover Critical Safari 9.1 Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-4589 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (mem WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4622, CVE-2016-4623, and CVE-2016-4624. NVD description · AI analysis pending | 8.8 | 3% |
| — |
Full article143 words · extracted from unit42.paloaltonetworks.com · click to collapse
Palo Alto Networks researchers were recently credited with the discovery of an Apple product vulnerability.
Researchers Tongbo Luo and Bo Qu discovered a WebKit vulnerability (CVE-2016-4589) affecting Safari in Apple iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later, and Apple TV (4th generation).
Apple addressed both findings in a recent security updates (HT206902 and HT206905) and are resolved in iOS 9.3.3 and tvOS 9.2.2. Palo Alto Networks also released IPS signatures covering these vulnerabilities (for current customers, available in content release 600).
Palo Alto Networks is a regular contributor to vulnerability research in Microsoft, Apple, Android and other ecosystems. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing the information with the security community, we are removing weapons used by attackers to threaten users and compromise enterprise, government and service provider networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/palo-alto-networks-researchers-discover-critical-safari-9-1-vulnerability/