WebKit in Apple iOS prior to 9.3.3, Safari prior to 9.1.2, and tvOS prior to 9.2.2 allows remote malicious users to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple webkit - |
||
webkitgtk webkitgtk\\+ |