First published: Fri May 20 2016(Updated: )
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <=9.1 | |
Apple iPhone OS | <=9.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1849 has been classified as a moderate severity vulnerability due to potential local access to sensitive data.
To fix CVE-2016-1849, update Apple Safari to version 9.1.1 or later and ensure iOS is updated to version 9.3.2 or above.
CVE-2016-1849 affects users of Apple Safari versions prior to 9.1.1 and iOS versions before 9.3.2.
CVE-2016-1849 is a local information disclosure vulnerability that can expose sensitive browsing data.
CVE-2016-1849 cannot be exploited remotely as it requires local access to a device.