First published: Fri Jul 22 2016(Updated: )
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebKit | ||
Apple Mobile Safari | <9.1.2 | |
iOS | <9.3.3 | |
tvOS | <9.2.2 | |
WebKitGTK+ | <2.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4592 is classified as a denial of service vulnerability impacting WebKit that can cause significant memory consumption.
To mitigate CVE-2016-4592, update your devices to the latest versions of iOS, Safari, or tvOS as specified in the patch releases.
CVE-2016-4592 affects WebKit in versions prior to 9.3.3, Safari versions before 9.1.2, and tvOS versions before 9.2.2.
CVE-2016-4592 affects Apple devices running iOS, Safari, and tvOS prior to the respective non-vulnerable versions.
Attackers can exploit CVE-2016-4592 through crafted websites that induce denial of service conditions via excessive memory consumption.