{"api_version":"1","generated_at":"2026-07-23T18:37:30+00:00","cve":"CVE-2016-4758","urls":{"html":"https://cve.report/CVE-2016-4758","api":"https://cve.report/api/cve/CVE-2016-4758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-4758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-4758"},"summary":{"title":"CVE-2016-4758","description":"WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.","state":"PUBLISHED","assigner":"apple","published_at":"2016-09-25 10:59:52","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html","name":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2016-09-20-2 Safari 10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT207143","name":"https://support.apple.com/HT207143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 10 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html","name":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2016-09-20-7 iTunes 12.5.1 for Windows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT207158","name":"https://support.apple.com/HT207158","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iTunes 12.5.1 for Windows - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1036854","name":"http://www.securitytracker.com/id/1036854","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Safari Multiple Bugs Let Remote Users Obtain Potentially Sensitive Information, Spoof the Address Bar, Conduct Cross-Site Scripting Attacks, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html","name":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MKSB(en): CVE-2016-4758: UXSS in Safari's showModalDialog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT207157","name":"https://support.apple.com/HT207157","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Safari 10 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93066","name":"http://www.securityfocus.com/bid/93066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html","name":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2016-09-20-3 iOS 10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-4758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"4758","vulnerable":"1","versionEndIncluding":"9.3.5","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4758","vulnerable":"1","versionEndIncluding":"12.4.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"itunes","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4758","vulnerable":"1","versionEndIncluding":"9.1.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4758","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"4758","cve":"CVE-2016-4758","epss":"0.009150000","percentile":"0.760130000","score_date":"2026-05-07","updated_at":"2026-05-08 00:14:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T00:39:26.118Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html"},{"name":"APPLE-SA-2016-09-20-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT207157"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT207158"},{"name":"93066","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93066"},{"name":"1036854","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1036854"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT207143"},{"name":"APPLE-SA-2016-09-20-7","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html"},{"name":"APPLE-SA-2016-09-20-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-09-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-29T09:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_MISC"],"url":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html"},{"name":"APPLE-SA-2016-09-20-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT207157"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT207158"},{"name":"93066","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93066"},{"name":"1036854","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1036854"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT207143"},{"name":"APPLE-SA-2016-09-20-7","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html"},{"name":"APPLE-SA-2016-09-20-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2016-4758","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html","refsource":"MISC","url":"http://mksben.l0.cm/2016/09/safari-uxss-showModalDialog.html"},{"name":"APPLE-SA-2016-09-20-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html"},{"name":"https://support.apple.com/HT207157","refsource":"CONFIRM","url":"https://support.apple.com/HT207157"},{"name":"https://support.apple.com/HT207158","refsource":"CONFIRM","url":"https://support.apple.com/HT207158"},{"name":"93066","refsource":"BID","url":"http://www.securityfocus.com/bid/93066"},{"name":"1036854","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1036854"},{"name":"https://support.apple.com/HT207143","refsource":"CONFIRM","url":"https://support.apple.com/HT207143"},{"name":"APPLE-SA-2016-09-20-7","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00012.html"},{"name":"APPLE-SA-2016-09-20-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00007.html"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2016-4758","datePublished":"2016-09-25T10:00:00.000Z","dateReserved":"2016-05-11T00:00:00.000Z","dateUpdated":"2024-08-06T00:39:26.118Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-09-25 10:59:52","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndIncluding":"9.1.3","matchCriteriaId":"A02241CD-8C84-46CA-AF77-7F9032836D20"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"9.3.5","matchCriteriaId":"5133BB4B-15AA-4F2F-B469-C5BD71FCE9C8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*","versionEndIncluding":"12.4.3","matchCriteriaId":"FA364FEA-190C-4C19-BEFF-6171CDBDEFB7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"4758","Ordinal":"1","Title":"CVE-2016-4758","CVE":"CVE-2016-4758","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"4758","Ordinal":"1","NoteData":"WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.","Type":"Description","Title":"CVE-2016-4758"},{"CveYear":"2016","CveId":"4758","Ordinal":"2","NoteData":"2016-09-25","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"4758","Ordinal":"3","NoteData":"2017-07-29","Type":"Other","Title":"Modified"}]}}}