CVE-2014-4467

Severity CVSS v4.0:
Pending analysis
Type:
CWE-17 Code Errors
Publication date:
30/01/2015
Last modified:
12/04/2025

Description

WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 8.1.2 (including)