CVE-2016-1864 describes a vulnerability in the XSS auditor of WebKit, affecting Apple iOS before version 9.3 and Safari before 9.1. This flaw allows remote attackers to obtain sensitive information due to improper handling of redirects in block mode when a crafted URL is accessed. Rated as Medium severity with a CVSS score of 4.3, it has a low attack complexity and requires no user interaction, potentially leading to a loss of confidentiality. There is no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
<= 9.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.