VULNERABILITY INTELLIGENCE

CVE-2016-4591

CVSS score7.8 HIGH
EPSS probability4.26%
CISA KEVNot currently listed
Published2016-07-22
Last modified2026-06-17

Description

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.