PT-2015-2084 · Apple · Webkit+1
Chris Evans
+1
·
Published
2015-09-18
·
Updated
2016-12-22
·
CVE-2015-5826
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 9
Description
The issue is related to the WebKit component in Apple iOS, which has inadequate access control. This allows remote attackers to bypass the Same Origin Policy by creating a crafted web site. The problem stems from WebKit not properly selecting the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type.
Recommendations
For Apple iOS versions prior to 9, update to a version 9 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious web sites to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webkit
Ios