First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iOS | <=10.1.1 | |
Apple Mobile Safari | <=10.0.1 | |
Apple iCloud for Windows | <=6.0.1 | |
Apple iTunes for Windows | <=12.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7592 has been classified as a medium severity vulnerability.
To remediate CVE-2016-7592, update affected Apple products to the latest versions available.
CVE-2016-7592 affects iOS versions before 10.2, Safari versions before 10.0.2, iCloud versions before 6.1, and iTunes versions before 12.5.4.
CVE-2016-7592 is a web vulnerability involving the WebKit component that can lead to sensitive information disclosure.
Yes, CVE-2016-7592 can be exploited remotely by attackers using crafted Java content.