WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to bypass a Content Security Policy protection mechanism by using a video control in conjunction with an IMG element within an OBJECT element.
2015-08-16T23:59:24.470
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apple | safari | < 6.2.8 | Yes |
| Application | apple | safari | < 7.1.8 | Yes |
| Application | apple | safari | < 8.0.8 | Yes |
| Operating System | apple | iphone_os | < 8.4.1 | Yes |