First published: Sun Sep 25 2016(Updated: )
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=9.3.5 | |
Apple iOS and macOS | <=10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4707 is classified as a moderate severity vulnerability in Apple iOS and macOS.
To address CVE-2016-4707, users should update their devices to iOS 10 or macOS 10.12 or later.
CVE-2016-4707 exploits a mishandling of Local Storage deletion in CFNetwork.
CVE-2016-4707 affects users of Apple iOS versions prior to 10 and macOS versions prior to 10.12.
The potential impacts of CVE-2016-4707 include unauthorized discovery of visited websites by local users.