CVE-2016-1785

MEDIUM

WebKit - Info Disclosure

Title source: llm

Description

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

Scores

CVSS v3 6.5
EPSS 0.0043
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (2)

apple/safari < 9.0.3
apple/iphone_os < 9.2.1

Timeline

Published Mar 24, 2016
Tracked Since Feb 18, 2026