A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93851 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2016/Oct/89 | third party advisory mailing list |
http://www.securitytracker.com/id/1037087 | vdb entry third party advisory |
https://packetstormsecurity.com/files/cve/CVE-2016-4676 | vdb entry third party advisory |
https://lists.apple.com/archives/security-announce/2016/Oct/msg00002.html | mailing list vendor advisory |