The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html | vendor advisory |
http://www.securitytracker.com/id/1035353 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html | vendor advisory |
http://www.securityfocus.com/archive/1/537948/100/0/threaded | mailing list |
https://support.apple.com/HT206171 | vendor advisory |
https://support.apple.com/HT206166 | vendor advisory |