PT-2008-5526 · Apple · Ios+2
Published
2008-11-25
·
Updated
2022-08-09
·
CVE-2008-4233
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Safari in Apple iPhone OS versions 1.0 through 2.1
Safari in Apple iPhone OS for iPod touch versions 1.1 through 2.1
Description:
The issue allows remote attackers to make arbitrary phone calls via a crafted HTML document because Safari does not isolate the call-approval dialog from the process of launching new applications.
Recommendations:
For Apple iPhone OS versions 1.0 through 2.1, consider disabling the launch of new applications from within Safari until a fix is available.
For Apple iPhone OS for iPod touch versions 1.1 through 2.1, restrict access to Safari when making phone calls to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safari
Ios
Ipod Touch