CVE-2016-4763
Apple Security Advisory 2016-09-20-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
WKWebView en WebKit en Apple iOS en versiones anteriores a 10, iTunes en versiones anteriores a 12.5.1 en Windows y Safari en versiones anteriores a 10 no verifica correctamente certificados X.509 desde servidores HTTPS, lo que permite a atacantes man-in-the-middle suplantar servidores y obtener información sensible a través de un certificado manipulado.
Safari 10 is now available and addresses cross site scripting, code execution, and various other vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-11 CVE Reserved
- 2016-09-20 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93066 | Vdb Entry | |
http://www.securitytracker.com/id/1036854 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html | 2017-07-30 | |
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html | 2017-07-30 | |
http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html | 2017-07-30 | |
https://support.apple.com/HT207143 | 2017-07-30 | |
https://support.apple.com/HT207157 | 2017-07-30 | |
https://support.apple.com/HT207158 | 2017-07-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | <= 12.4.3 Search vendor "Apple" for product "Itunes" and version " <= 12.4.3" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | <= 9.1.3 Search vendor "Apple" for product "Safari" and version " <= 9.1.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | <= 9.3.5 Search vendor "Apple" for product "Iphone Os" and version " <= 9.3.5" | - |
Affected
|