VYPR
Unrated severityNVD Advisory· Published Mar 14, 2009· Updated Apr 23, 2026

CVE-2009-0143

CVE-2009-0143

Description

Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.