CVE-2016-1842

HIGH

Apple iOS <9.3.2, OS X <10.11.5, watchOS <2.2.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206567
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206566
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00003.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035890
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206568

Scores

CVSS v3 7.5
EPSS 0.0227
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284
Status published
Products (3)
apple/iphone_os < 9.3.1
apple/mac_os_x < 10.11.4
apple/watchos < 2.2
Published May 20, 2016
Tracked Since Feb 18, 2026