First published: Thu Jun 24 2010(Updated: )
WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebKit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2441 has been classified as a vulnerability that poses a moderate risk due to the ability for remote attackers to read keystrokes.
To mitigate CVE-2010-2441, ensure that you are using the latest version of Apple WebKit, as subsequent updates address this vulnerability.
CVE-2010-2441 enables remote attackers to potentially capture users' keystrokes through cross-domain IFRAME gadgets.
CVE-2010-2441 affects Apple WebKit across various versions.
Yes, CVE-2010-2441 can be exploited in phishing attacks to capture sensitive user input by manipulating focus changes.