CVE-2014-4467

iPhone OS < 8.1.3 - UI Spoofing via WebKit Frame Scrollbar Rendering

Title source: llm
STIX 2.1

Description

WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/HT204245
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html

Scores

EPSS 0.0115
EPSS Percentile 63.5%

Details

CWE
CWE-17
Status published
Products (1)
apple/iphone_os < 8.1.2
Published Jan 30, 2015
Tracked Since Feb 18, 2026