CVE-2016-4763

MEDIUM

Apple Itunes < 12.4.3 - Cryptographic Issue

Title source: rule

Description

WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Scores

CVSS v3 6.8
EPSS 0.0017
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-310
Status published

Affected Products (4)

apple/itunes < 12.4.3
apple/safari < 9.1.3
apple/iphone_os < 9.3.5
n/a/n/a

Timeline

Published Sep 25, 2016
Tracked Since Feb 18, 2026