VulnerabilityModified
CVE-2016-4603
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
MEDIUM 4.3EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- apple/iphone os
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlMailing List
- http://www.securityfocus.com/bid/91825
- http://www.securitytracker.com/id/1036344
- https://support.apple.com/HT206902Vendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlMailing List
- http://www.securityfocus.com/bid/91825
- http://www.securitytracker.com/id/1036344
- https://support.apple.com/HT206902Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.