CVE-2008-4232

Safari - User Interface Spoofing via IFRAME Boundary Bypass

Title source: llm
STIX 2.1

Description

Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50029
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3232
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3318
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021272
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32394
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32756

Scores

EPSS 0.0216
EPSS Percentile 80.3%

Details

Status published
Products (14)
apple/iphone_os 1.0
apple/iphone_os 1.0.1
apple/iphone_os 1.0.2
apple/iphone_os 1.1
apple/iphone_os 1.1.1
apple/iphone_os 1.1.2
apple/iphone_os 1.1.3
apple/iphone_os 1.1.4
apple/iphone_os 1.1.5
apple/iphone_os 2.0
... and 4 more
Published Nov 25, 2008
Tracked Since Feb 18, 2026