Medium severity4.3NVD Advisory· Published Feb 1, 2016· Updated Jun 17, 2026
CVE-2016-1728
CVE-2016-1728
Description
The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <9.2.1
<9.0.3+ 1 more
- (no CPE)range: <9.0.3
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <=9.0.2
Patches
Vulnerability mechanics
References
9- lists.apple.com/archives/security-announce/2016/Jan/msg00002.htmlnvdVendor Advisory
- lists.apple.com/archives/security-announce/2016/Jan/msg00004.htmlnvdVendor Advisory
- support.apple.com/HT205730nvdVendor Advisory
- support.apple.com/HT205732nvdVendor Advisory
- packetstormsecurity.com/files/136227/WebKitGTK-Memory-Corruption-Denial-Of-Service.htmlnvd
- www.securityfocus.com/archive/1/537771/100/0/threadednvd
- www.securityfocus.com/bid/81263nvd
- www.securitytracker.com/id/1034737nvd
- security.gentoo.org/glsa/201706-15nvd
News mentions
0No linked articles in our index yet.