First published: Sun Sep 25 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =9.1.3 | |
iStyle @cosme iPhone OS | <=9.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4618 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
The fix for CVE-2016-4618 involves updating Safari and iOS to versions 10 or later.
CVE-2016-4618 affects Safari versions prior to 10 and iOS versions up to 9.3.5.
CVE-2016-4618 allows remote attackers to inject arbitrary web scripts or HTML through crafted websites.
CVE-2016-4618 is no longer a threat in systems running Safari and iOS versions 10 and above.