CVE-2010-1407: Infoleak
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1407?
CVE-2010-1407 is classified with a moderate severity due to potential exposure of sensitive information to remote attackers.
How do I fix CVE-2010-1407?
The best way to address CVE-2010-1407 is to update your device to Apple iOS version 4 or later.
Which devices are affected by CVE-2010-1407?
CVE-2010-1407 affects Apple iOS devices like the iPhone and iPod touch running versions prior to 4.
What type of attack does CVE-2010-1407 allow?
CVE-2010-1407 allows remote attackers to execute a crafted HTML document that can reveal sensitive information.
Can CVE-2010-1407 be exploited remotely?
Yes, CVE-2010-1407 can be exploited remotely through malicious web content targeting affected devices.