CVE-2016-4603
published 2016-07-22CVE-2016-4603: Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by…
PriorityP417medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.20%
65.0th percentile
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.2 | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4603: iOS 9.3.3
vendor_apple·2016-07-18·CVSS 4.3
CVE-2016-4603 [MEDIUM] CVE-2016-4603: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4603
Component: Web Media
Impact: Viewing a video in Safari's Private Browsing mode displays the URL of the video outside of Private Browsing mode
Description: A privacy issue existed in the handling of user data by Safari View Controller. This issue was addressed through improved state management.
GHSA
GHSA-8h3m-72q2-6wfr: Web Media in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2016-4603 [MEDIUM] GHSA-8h3m-72q2-6wfr: Web Media in Apple iOS before 9
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://www.securityfocus.com/bid/91825http://www.securitytracker.com/id/1036344https://support.apple.com/HT206902http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://www.securityfocus.com/bid/91825http://www.securitytracker.com/id/1036344https://support.apple.com/HT206902
2016-07-22
Published