CVE-2016-1781
MEDIUMSafari < 9.1 - User Tracking via WebKit Attachment URL Handling
Title source: llmDescription
WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205635
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1035353
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537948/100/0/threaded
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00003.html
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205639
Scores
CVSS v3
4.3
EPSS
0.0129
EPSS Percentile
67.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Details
CWE
CWE-19
Status
published
Products (2)
apple/iphone_os
< 9.2.1
apple/safari
< 9.0.3
Published
Mar 24, 2016
Tracked Since
Feb 18, 2026