CVE-2016-4583

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
22/07/2016
Last modified:
12/04/2025

Description

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:webkit:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 9.1.2 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 9.3.3 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 9.2.2 (excluding)
cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:* 2.12.2 (excluding)