Medium severity4.3NVD Advisory· Published Mar 24, 2016· Updated May 6, 2026
CVE-2016-1764
CVE-2016-1764
Description
The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlnvdVendor Advisory
- support.apple.com/HT206167nvdVendor Advisory
- www.securitytracker.com/id/1035363nvd
News mentions
0No linked articles in our index yet.