The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2012/Sep/msg00005.html | vendor advisory |
http://support.apple.com/kb/HT5502 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78681 | vdb entry |
http://osvdb.org/85653 | vdb entry |
http://www.securityfocus.com/bid/55625 | vdb entry |