First published: Fri May 20 2016(Updated: )
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | <9.1.1 | |
iPhone OS | <9.3.2 | |
tvOS | <9.2.1 | |
WebKitGTK+ | <2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1858 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2016-1858, update your affected Apple devices to the latest versions of iOS, Safari, or tvOS.
CVE-2016-1858 affects Apple iOS versions before 9.3.2, Safari versions before 9.1.1, and tvOS versions before 9.2.1.
CVE-2016-1858 exploits improper tracking of taint attributes in WebKit, which can lead to information disclosure.
Remote attackers can target users of affected Apple products via a crafted website to exploit CVE-2016-1858.