First published: Fri Jul 22 2016(Updated: )
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Webkit | ||
Apple Safari | <9.1.2 | |
Apple iPhone OS | <9.3.3 | |
tvOS | <9.2.2 | |
WebKitGTK+ | <2.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4583 is considered to have a moderate severity due to its ability to bypass the Same Origin Policy.
To fix CVE-2016-4583, update to iOS version 9.3.3, Safari version 9.1.2, or tvOS version 9.2.2 or later.
CVE-2016-4583 affects Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2.
Yes, CVE-2016-4583 can be exploited remotely via a timing attack involving an SVG document.
The impact of CVE-2016-4583 is the potential unauthorized access to image data from unintended websites.