WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to access file: URLs by leveraging a URL drag operation that originates at a crafted web site.
http://www.securitytracker.com/id/1030495
http://archives.neohapsis.com/archives/bugtraq/2014-06/0171.html