First published: Fri Jul 22 2016(Updated: )
WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebKit | ||
iStyle @cosme iPhone OS | <9.3.3 | |
tvOS | <9.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4587 is classified as a medium severity vulnerability due to its potential to leak sensitive information.
To fix CVE-2016-4587, update your iOS devices to version 9.3.3 or later and tvOS devices to version 9.2.2 or later.
CVE-2016-4587 affects devices running versions of Apple iOS before 9.3.3 and tvOS before 9.2.2.
If CVE-2016-4587 is not addressed, attackers could exploit it to access uninitialized memory, potentially revealing sensitive data.
Yes, CVE-2016-4587 can be exploited remotely through crafted web sites targeted at vulnerable Apple devices.