WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html | mailing list vendor advisory |
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/91830 | vdb entry third party advisory |
https://support.apple.com/HT206900 | vendor advisory |
http://www.securitytracker.com/id/1036343 | vdb entry third party advisory |
http://packetstormsecurity.com/files/138502/WebKitGTK-SOP-Bypass-Information-Disclosure.html | vdb entry third party advisory |
http://www.securityfocus.com/archive/1/539295/100/0/threaded | mailing list vdb entry third party advisory |
https://support.apple.com/HT206905 | vendor advisory |
https://support.apple.com/HT206902 | vendor advisory |
http://lists.apple.com/archives/security-announce/2016/Jul/msg00004.html | mailing list vendor advisory |