CVE-2006-0848 describes a vulnerability in Apple Safari on Mac OS X where the "Open 'safe' files after downloading" option can lead to remote code execution. Attackers can trick users into downloading a specially crafted archive (e.g., ZIP) containing a __MACOSX folder with metadata that invokes Terminal to execute a script. This user-assisted attack has a CVSS score of 5.1, indicating partial confidentiality, integrity, and availability impact due to high attack complexity. Although not in CISA's KEV catalog, a Metasploit module exists, and its EPSS score of 0.83 suggests a high likelihood of exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.4.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:* | ||
10.4.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.