Medium severity4.3NVD Advisory· Published Jun 19, 2016· Updated Jun 17, 2026
CVE-2016-1864
CVE-2016-1864
Description
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <=9.0.3
- (no CPE)range: <9.1
- Range: <9.3
Patches
Vulnerability mechanics
References
6- lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlnvdVendor Advisory
- lists.apple.com/archives/security-announce/2016/Mar/msg00005.htmlnvdVendor Advisory
- support.apple.com/HT206166nvdVendor Advisory
- support.apple.com/HT206171nvdVendor Advisory
- www.securityfocus.com/bid/91358nvd
- www.securitytracker.com/id/1036344nvd
News mentions
0No linked articles in our index yet.