First published: Thu Mar 24 2016(Updated: )
Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=9.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2197 is considered a medium severity vulnerability due to its potential for user interface spoofing.
To fix CVE-2009-2197, update Apple Safari to version 9.1 or later.
CVE-2009-2197 allows remote attackers to spoof the user interface, potentially misleading users into interacting with malicious content.
CVE-2009-2197 affects all versions of Apple Safari prior to 9.1.
While there may not be publicly known exploits for CVE-2009-2197, the vulnerability itself poses a significant risk for phishing and other social engineering attacks.