CVE-2016-4728

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/09/2016
Last modified:
12/04/2025

Description

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 10.0 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 10.0 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 10.0 (excluding)
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* 12.5.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*