High severity7.5NVD Advisory· Published Feb 3, 2020· Updated Jun 17, 2026
CVE-2016-4676
CVE-2016-4676
Description
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<10.0.1+ 2 more
- (no CPE)range: <10.0.1
- (no CPE)range: before 10.0.1
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <10.0.1
cpe:2.3:o:apple:mac_os_x:10.10.5:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:mac_os_x:10.10.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.11.6:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.12:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- seclists.org/fulldisclosure/2016/Oct/89nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/93851nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037087nvdThird Party AdvisoryVDB Entry
- lists.apple.com/archives/security-announce/2016/Oct/msg00002.htmlnvdMailing ListVendor Advisory
- packetstormsecurity.com/files/cve/CVE-2016-4676nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.