First published: Mon Feb 03 2020(Updated: )
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <10.0.1 | |
macOS Yosemite | =10.10.5 | |
macOS Yosemite | =10.11.6 | |
macOS Yosemite | =10.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4676 has a medium severity rating due to its potential to expose sensitive information.
To fix CVE-2016-4676, update Safari to version 10.0.1 or later.
CVE-2016-4676 affects Apple Safari versions prior to 10.0.1 and specific versions of macOS Yosemite.
CVE-2016-4676 is a cross-origin vulnerability related to the processing of location attributes in WebKit.
Yes, CVE-2016-4676 can allow a remote malicious user to obtain sensitive information from vulnerable systems.