CVE-2016-8507: Infoleak
Published Mar 1, 2017
·Updated
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
Affected Software
1 affected component
Yandex Yandex Browser Iphone Os<16.10.0.2357
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8507?
CVE-2016-8507 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to video and audio data.
2
How do I fix CVE-2016-8507?
To fix CVE-2016-8507, update the Yandex Browser to version 16.10.0.2358 or later.
3
What type of attacks does CVE-2016-8507 enable?
CVE-2016-8507 enables remote attackers to initiate FaceTime calls without user consent.
4
Which versions of Yandex Browser are affected by CVE-2016-8507?
CVE-2016-8507 affects Yandex Browser versions prior to 16.10.0.2357.
5
What can attackers access through CVE-2016-8507?
Attackers can access video and audio data from a device exploited via a crafted website due to CVE-2016-8507.