CVE-2016-1864
N/A
N/A
Summary
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securitytracker.com/id/1036344
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- https://support.apple.com/HT206171
- http://www.securityfocus.com/bid/91358
- https://support.apple.com/HT206166
References
- http://www.securitytracker.com/id/1036344
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- https://support.apple.com/HT206171
- http://www.securityfocus.com/bid/91358
- https://support.apple.com/HT206166
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.