Уязвимость обхода политики одного происхождения (Same Origin Policy) в iOS, iPadOS, tvOS, macOS Ventura, Safari и watchOS
Описание
Проблема решена благодаря улучшенным проверкам. Веб-сайт был способен обойти политику одного происхождения (Same Origin Policy).
Затронутые версии ПО
- iOS < 15.7.8
- iPadOS < 15.7.8
- iOS < 16.6
- iPadOS < 16.6
- tvOS < 16.6
- macOS Ventura < 13.5
- Safari < 16.6
- watchOS < 9.6
Тип уязвимости
Обход политики одного происхождения (Same Origin Policy)
Ссылки
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
Дефекты
Связанные уязвимости
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.
The issue was addressed with improved checks. This issue is fixed in i ...
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, watchOS 9.6, macOS Ventura 13.5, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.6. A website may be able to bypass Same Origin Policy.
Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit операционных систем iOS, iPadOS, tvOS, macOS, watchOS, браузера Safari, позволяющая нарушителю обойти существующие ограничения безопасности
EPSS
7.5 High
CVSS3