CVE-2016-1849

low

Description

The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.

References

https://support.apple.com/HT206568

https://support.apple.com/HT206565

http://www.securitytracker.com/id/1035888

http://lists.apple.com/archives/security-announce/2016/May/msg00005.html

http://lists.apple.com/archives/security-announce/2016/May/msg00002.html

Details

Source: Mitre, NVD

Published: 2016-05-20

Updated: 2016-12-01

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low