First published: Tue Jun 22 2010(Updated: )
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <4.0 | |
Apple iPod touch | ||
iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1757 is classified as a medium severity vulnerability.
CVE-2010-1757 allows remote attackers to spoof the user interface on Apple iOS devices by exploiting the IFRAME boundary restrictions.
CVE-2010-1757 affects Apple iOS versions prior to 4.0 on iPhone and iPod touch.
To fix CVE-2010-1757, users should update their Apple iOS devices to version 4.0 or later.
CVE-2010-1757 enables attackers to perform user interface spoofing through a crafted HTML document.