CVE-2015-3753

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
16/08/2015
Last modified:
12/04/2025

Description

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 6.0 (including) 6.2.8 (excluding)
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 7.0 (including) 7.1.8 (excluding)
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 8.0 (including) 8.0.8 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 8.4.1 (excluding)