First published: Fri Jul 22 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Webkit | ||
Apple Safari | <9.1.2 | |
Apple iPhone OS | <9.3.3 | |
Apple tvOS | <9.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.