CVE-2016-1780
published 2016-03-24CVE-2016-1780: WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive…
PriorityP417medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.24%
66.3th percentile
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | <= 45.0.2 | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chfr-83gv-5hhp: WebKit in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2016-1780 [MEDIUM] CWE-200 GHSA-chfr-83gv-5hhp: WebKit in Apple iOS before 9
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
GHSA
GHSA-x4mq-76g8-78f6: Mozilla Firefox before 46
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2016-2813 [MEDIUM] CWE-200 GHSA-x4mq-76g8-78f6: Mozilla Firefox before 46
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
OSV
CVE-2016-1780: WebKit in Apple iOS before 9
osv·2016-03-24·CVSS 4.3
CVE-2016-1780 [MEDIUM] CVE-2016-1780: WebKit in Apple iOS before 9
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
Red Hat
Mozilla: Disclosure of user actions through JavaScript with motion and orientation sensors (MFSA 2016-43)
vendor_redhat·2016-04-26·CVSS 4.3
CVE-2016-2813 [MEDIUM] Mozilla: Disclosure of user actions through JavaScript with motion and orientation sensors (MFSA 2016-43)
Mozilla: Disclosure of user actions through JavaScript with motion and orientation sensors (MFSA 2016-43)
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-2813: firefox - Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript acc...
vendor_debian·2016·CVSS 4.3
CVE-2016-2813 [MEDIUM] CVE-2016-2813: firefox - Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript acc...
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
Scope: local
sid: resolved
Apple
CVE-2016-1780: iOS 9.3
vendor_apple·CVSS 4.3
CVE-2016-1780 [MEDIUM] CVE-2016-1780: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1780
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-03-24
Published