First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=10.1.1 | |
Apple iCloud for Windows | <=6.0.1 | |
Apple iTunes for Windows | <=12.5.3 | |
Apple Mobile Safari | <=10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7599 is classified as a high-severity vulnerability due to its potential to allow remote attackers to bypass Same Origin Policy protections.
To fix CVE-2016-7599, ensure that your Apple devices and software are updated to the latest versions available, specifically iOS 10.2 or higher, Safari 10.0.2 or higher, iCloud 6.1 or higher, and iTunes 12.5.4 or higher.
CVE-2016-7599 affects iOS versions prior to 10.2.
CVE-2016-7599 involves the WebKit component, which is used by browsers and other applications for rendering web content.
Devices running affected versions of iOS, Safari, iCloud, and iTunes, such as iPhones and iPads, are vulnerable to CVE-2016-7599.