CVE-2016-1849

low

Description

The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.

References

http://lists.apple.com/archives/security-announce/2016/May/msg00002.html

http://lists.apple.com/archives/security-announce/2016/May/msg00005.html

https://support.apple.com/HT206565

https://support.apple.com/HT206568

http://www.securitytracker.com/id/1035888

Details

Source: Mitre, NVD

Published: 2016-05-20

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low