CVE-2016-1842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
20/05/2016
Last modified:
06/05/2026

Description

MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 9.3.1 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.11.4 (including)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 2.2 (including)