The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html | vendor advisory |
http://lists.apple.com/archives/security-announce/2015/Mar/msg00004.html | vendor advisory |
http://www.securitytracker.com/id/1031936 | vdb entry |
https://support.apple.com/HT204560 | vendor advisory |
https://support.apple.com/HT204661 | vendor advisory |