{"api_version":"1","generated_at":"2026-07-24T02:23:37+00:00","cve":"CVE-2016-1785","urls":{"html":"https://cve.report/CVE-2016-1785","api":"https://cve.report/api/cve/CVE-2016-1785.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-1785","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-1785"},"summary":{"title":"CVE-2016-1785","description":"The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.","state":"PUBLISHED","assigner":"apple","published_at":"2016-03-24 01:59:52","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html","name":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2016-03-21-6 Safari 9.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT206171","name":"https://support.apple.com/HT206171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Safari 9.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/537948/100/0/threaded","name":"http://www.securityfocus.com/archive/1/537948/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2016-03-21-1 iOS 9.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1035353","name":"http://www.securitytracker.com/id/1035353","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code and Let Remote and Local Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT206166","name":"https://support.apple.com/HT206166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 9.3 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-1785","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1785","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"1785","vulnerable":"1","versionEndIncluding":"9.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"1785","vulnerable":"1","versionEndIncluding":"9.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:10:39.892Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"APPLE-SA-2016-03-21-6","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html"},{"name":"1035353","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1035353"},{"name":"APPLE-SA-2016-03-21-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html"},{"name":"20160331 WebKitGTK+ Security Advisory WSA-2016-0003","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/537948/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT206171"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT206166"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-03-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"APPLE-SA-2016-03-21-6","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html"},{"name":"1035353","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1035353"},{"name":"APPLE-SA-2016-03-21-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html"},{"name":"20160331 WebKitGTK+ Security Advisory WSA-2016-0003","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/537948/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT206171"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT206166"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2016-1785","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"APPLE-SA-2016-03-21-6","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00005.html"},{"name":"1035353","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1035353"},{"name":"APPLE-SA-2016-03-21-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html"},{"name":"20160331 WebKitGTK+ Security Advisory WSA-2016-0003","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/537948/100/0/threaded"},{"name":"https://support.apple.com/HT206171","refsource":"CONFIRM","url":"https://support.apple.com/HT206171"},{"name":"https://support.apple.com/HT206166","refsource":"CONFIRM","url":"https://support.apple.com/HT206166"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2016-1785","datePublished":"2016-03-24T01:00:00.000Z","dateReserved":"2016-01-13T00:00:00.000Z","dateUpdated":"2024-08-05T23:10:39.892Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-03-24 01:59:52","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0.3","matchCriteriaId":"F39FC2FB-375B-4129-A37F-BC749F8A9648"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"9.2.1","matchCriteriaId":"080450EA-85C1-454D-98F9-5286D69CF237"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"1785","Ordinal":"1","Title":"CVE-2016-1785","CVE":"CVE-2016-1785","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"1785","Ordinal":"1","NoteData":"The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.","Type":"Description","Title":"CVE-2016-1785"},{"CveYear":"2016","CveId":"1785","Ordinal":"2","NoteData":"2016-03-23","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"1785","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}