5
CVSSv2

CVE-2015-3753

Published: 16/08/2015 Updated: 07/02/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

WebKit in Apple Safari prior to 6.2.8, 7.x prior to 7.1.8, and 8.x prior to 8.0.8, as used in iOS prior to 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote malicious users to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple iphone os