CVE-2016-1864
Description
The XSS auditor in WebKit fails to handle redirects in block mode, allowing information disclosure via crafted URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The XSS auditor in WebKit fails to handle redirects in block mode, allowing information disclosure via crafted URLs.
Vulnerability
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode. This allows a remote attacker to obtain sensitive information via a crafted URL. [1][2]
Exploitation
An attacker can craft a URL that triggers the XSS auditor's block mode, but due to improper redirect handling, the auditor may leak information about the page content. The attacker needs to lure the victim to visit the malicious URL, possibly via a link or embedded content. No authentication is required.
Impact
Successful exploitation could lead to disclosure of sensitive information from the context of the vulnerable browser. The attacker gains information that the XSS auditor was intended to protect, potentially bypassing same-origin policy restrictions.
Mitigation
Apple addressed this issue in iOS 9.3 and Safari 9.1. Users should update to these versions or later. No workarounds are documented. [1][2]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <=9.0.3
- (no CPE)range: <9.1
- Range: <9.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlnvdVendor Advisory
- lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlnvdVendor Advisory
- support.apple.com/HT206166nvdVendor Advisory
- support.apple.com/HT206171nvdVendor Advisory
- www.securityfocus.com/bid/91358nvd
- www.securitytracker.com/id/1036344nvd
News mentions
0No linked articles in our index yet.