CVE-2013-0974

iPhone OS < 6.1 - JavaScript Execution Bypass via Smart App Banner

Title source: llm
STIX 2.1

Description

StoreKit in Apple iOS before 6.1 does not properly handle the disabling of JavaScript within the preferences configuration of Mobile Safari, which allows remote attackers to bypass intended access restrictions and execute JavaScript code via a web site with a Smart App Banner.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5642
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/89658
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html

Scores

EPSS 0.0123
EPSS Percentile 65.9%

Details

Status published
Products (3)
apple/iphone_os 6.0
apple/iphone_os 6.0.1
apple/iphone_os < 6.0.2
Published Jan 29, 2013
Tracked Since Feb 18, 2026