Apple iOS WebKit information leakage (CVE-2016-1864)
Apple iOS WebKit information leakage (CVE-2016-1864)
Release date:
Updated on:
Affected Systems:
Apple iOS <9.3
Apple iOS <9.1
Description:
CVE (CAN) ID: CVE-2016-1864
IOS is an operating system developed by Apple for mobile devices. It supports iPhone, iPod touch, iPad, and Apple TV.
For Apple iOS <9.3 and Safari <9.1, WebKit XSS auditor does not properly process redirection in block mode. Remote attackers can obtain sensitive information by constructing URLs.
<* Source: Apple
*>
Suggestion:
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://support.apple.com/HT206171
Https://support.apple.com/HT206166
Http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
Http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html
This article permanently updates the link address: