CVE-2016-1781

MEDIUM

Safari < 9.1 - User Tracking via WebKit Attachment URL Handling

Title source: llm
STIX 2.1

Description

WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205635
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035353
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537948/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00003.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205639

Scores

CVSS v3 4.3
EPSS 0.0129
EPSS Percentile 67.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-19
Status published
Products (2)
apple/iphone_os < 9.2.1
apple/safari < 9.0.3
Published Mar 24, 2016
Tracked Since Feb 18, 2026