Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.
2015-08-16T23:59:01.410
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | < 6.2.8 | Yes |
Application | apple | safari | < 7.1.8 | Yes |
Application | apple | safari | < 8.0.8 | Yes |
Operating System | apple | iphone_os | < 8.4.1 | No |