WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
https://exchange.xforce.ibmcloud.com/vulnerabilities/66000
http://www.securitytracker.com/id?1025182
http://www.securityfocus.com/bid/46814
http://support.apple.com/kb/HT4566
http://support.apple.com/kb/HT4564
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html