PT-2016-1528 · Apple · Webkit+1
Ehsan Toreini
+3
·
Published
2016-03-24
·
Updated
2016-12-03
·
CVE-2016-1780
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 9.3
Description
The issue allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site, by exploiting a lack of protection for certain data in the WebKit component. This could potentially reveal confidential information about the device.
Recommendations
For iOS versions prior to 9.3, update to iOS 9.3 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webkit
Ios