WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade webkit2gtk | Oct 1, 2024 | Jul 22, 2016 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 9.1.2 | Dec 5, 2016 | Jul 21, 2016 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Jul 22, 2016 |
| Suse | — | Upgrade libwebkit2gtk3-langUpgrade libjavascriptcoregtk-4_0-18Upgrade webkit2gtk-4_0-injected-bundlesUpgrade typelib-1_0-javascriptcore-4_0Upgrade libwebkit2gtk-4_0-37Upgrade typelib-1_0-webkit2webextension-4_0Upgrade typelib-1_0-webkit2-4_0Upgrade webkit2gtk3-devel | Dec 9, 2016 | Jul 21, 2016 |
| Ubuntu | — | Upgrade libwebkit2gtk-4.0-37Upgrade libjavascriptcoregtk-4.0-18 | Sep 15, 2016 | Jul 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub