The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.
2015-03-18T22:59:15.127
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | iphone_os | ≤ 8.2 | Yes |
Application | apple | safari | ≤ 6.2.3 | Yes |
Application | apple | safari | 7.0 | Yes |
Application | apple | safari | 7.0.1 | Yes |
Application | apple | safari | 7.0.2 | Yes |
Application | apple | safari | 7.0.3 | Yes |
Application | apple | safari | 7.0.4 | Yes |
Application | apple | safari | 7.0.5 | Yes |
Application | apple | safari | 7.0.6 | Yes |
Application | apple | safari | 7.1.0 | Yes |
Application | apple | safari | 7.1.1 | Yes |
Application | apple | safari | 7.1.2 | Yes |
Application | apple | safari | 7.1.3 | Yes |
Application | apple | safari | 8.0.0 | Yes |
Application | apple | safari | 8.0.1 | Yes |
Application | apple | safari | 8.0.2 | Yes |
Application | apple | safari | 8.0.3 | Yes |