PT-2017-4189 · Yandex · Yandex Browser

Publicado

2017-03-01

·

Atualizado

2020-07-09

·

CVE-2016-8507

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yandex Browser for iOS versions prior to 16.10.0.2357
Description The issue is related to improper restriction of processing of facetime:// URLs, which allows remote attackers to initiate a facetime call without the user's approval and obtain video and audio data from a device via a crafted web site. The vulnerability is associated with errors in checking URLs with the facetime:// scheme, allowing a remote attacker to initiate a video call without notifying the user.
Recommendations For Yandex Browser for iOS versions prior to 16.10.0.2357, update to version 16.10.0.2357 or later to resolve the issue. As a temporary workaround, consider avoiding the use of facetime:// URLs in the affected browser until a patch is applied. Restrict access to the facetime functionality to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03577
CVE-2016-8507

Produtos afetados

Yandex Browser