CVE-2013-0974
iPhone OS < 6.1 - JavaScript Execution Bypass via Smart App Banner
Title source: llmDescription
StoreKit in Apple iOS before 6.1 does not properly handle the disabling of JavaScript within the preferences configuration of Mobile Safari, which allows remote attackers to bypass intended access restrictions and execute JavaScript code via a web site with a Smart App Banner.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5642
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/89658
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html
Scores
EPSS
0.0123
EPSS Percentile
65.9%
Details
Status
published
Products (3)
apple/iphone_os
6.0
apple/iphone_os
6.0.1
apple/iphone_os
< 6.0.2
Published
Jan 29, 2013
Tracked Since
Feb 18, 2026