CVE-2016-4707

MEDIUM

CFNetwork <10 - Info Disclosure

Title source: llm

Description

CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-19 CWE-200
Status published

Affected Products (3)

apple/iphone_os < 9.3.5
apple/mac_os_x < 10.11.6
n/a/n/a

Timeline

Published Sep 25, 2016
Tracked Since Feb 18, 2026