First published: Fri Jul 22 2016(Updated: )
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | ||
iStyle @cosme iPhone OS | <=9.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4604 is classified as a moderate vulnerability due to the potential for URL spoofing.
To fix CVE-2016-4604, update Safari or iOS to version 9.3.3 or later.
Safari versions prior to 9.3.3 are affected by CVE-2016-4604.
Yes, CVE-2016-4604 can be exploited remotely by attackers to spoof URLs.
CVE-2016-4604 may lead users to trust fraudulent URLs, posing security risks.