CVE-2016-1842
HIGHApple iOS <9.3.2, OS X <10.11.5, watchOS <2.2.1 - Info Disclosure
Title source: llmDescription
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206567
Mailing List, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206566
Mailing List, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00003.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1035890
Mailing List, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206568
Scores
CVSS v3
7.5
EPSS
0.0227
EPSS Percentile
80.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-284
Status
published
Products (3)
apple/iphone_os
< 9.3.1
apple/mac_os_x
< 10.11.4
apple/watchos
< 2.2
Published
May 20, 2016
Tracked Since
Feb 18, 2026