First published: Thu Aug 25 2016(Updated: )
Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Safe Browser | <=1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6231 is considered a high-severity vulnerability due to the potential for man-in-the-middle attacks that can expose sensitive data.
To resolve CVE-2016-6231, upgrade Kaspersky Safe Browser to version 1.7.0 or later.
CVE-2016-6231 allows man-in-the-middle attackers to intercept and access sensitive information via a rogue SSL certificate.
CVE-2016-6231 affects Kaspersky Safe Browser versions prior to 1.7.0.
If you must use an affected version of Kaspersky Safe Browser, consider using an alternative security solution until you can upgrade.