CVE-2016-1842
published 2016-05-20CVE-2016-1842: MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.27%
81.1th percentile
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.1 | — |
| apple | mac_os_x | <= 10.11.4 | — |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
| apple | watchos | <= 2.2 | — |
| apple | watchos | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-1842: watchOS 2.2.1
vendor_apple·CVSS 7.5
CVE-2016-1842 [HIGH] CVE-2016-1842: watchOS 2.2.1
Apple Security Update: About the security content of watchOS 2.2.1
Product: watchOS
Version: 2.2.1
CVE: CVE-2016-1842
Component: CVE-ID
Apple
CVE-2016-1842: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 7.5
CVE-2016-1842 [HIGH] CVE-2016-1842: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-1842
Component: CVE-ID
Apple
CVE-2016-1842: iOS 9.3.2
vendor_apple·CVSS 7.5
CVE-2016-1842 [HIGH] CVE-2016-1842: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1842
Component: CVE-ID
GHSA
GHSA-55p3-77g6-98rp: MapKit in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2016-1842 [HIGH] CWE-284 GHSA-55p3-77g6-98rp: MapKit in Apple iOS before 9
MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securitytracker.com/id/1035890https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568http://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securitytracker.com/id/1035890https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568
2016-05-20
Published