WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
2016-07-22T02:59:14.473
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:C/I:N/A:N
10.0
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apple | webkit | * | Yes |
| Application | apple | safari | < 9.1.2 | No |
| Operating System | apple | iphone_os | < 9.3.3 | No |
| Operating System | apple | tvos | < 9.2.2 | No |