VulnerabilityModified
CVE-2012-0585
The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.
MEDIUM 5.0EPSS 2.47%
Does this matter?
Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.
Description
The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.htmlMailing List, Vendor Advisory
- http://osvdb.org/79964Broken Link
- http://secunia.com/advisories/48288Third Party Advisory
- http://secunia.com/advisories/48377Third Party Advisory
- http://www.securitytracker.com/id?1026774Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73871Third Party Advisory, VDB Entry
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.htmlMailing List, Vendor Advisory
- http://osvdb.org/79964Broken Link
- http://secunia.com/advisories/48288Third Party Advisory
- http://secunia.com/advisories/48377Third Party Advisory
- http://www.securitytracker.com/id?1026774Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73871Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.