First published: Mon Apr 28 2008(Updated: )
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1999 is considered a moderate severity vulnerability due to its potential to allow address bar spoofing.
To mitigate CVE-2008-1999, users should upgrade to a newer version of Apple Safari that has patched this vulnerability.
CVE-2008-1999 specifically affects Apple Safari version 3.1.1.
CVE-2008-1999 exploits URL manipulation to spoof the address bar, leading users to believe they are visiting a legitimate site.
As of the latest reports, CVE-2008-1999 has not been widely exploited in the wild, but it poses a risk due to its nature.