vendor:
Safari
by:
Project Zero
8,8
CVSS
HIGH
Frame Detachment Vulnerability
20
CWE
Product Name: Safari
Affected Version From: Safari 10.0.2
Affected Version To: Safari 10.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:safari:10.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac
2017
Frame Detachment Vulnerability in Safari
The Frame::setDocument() function in Safari does not properly detach the frame from the cached document. This can be exploited to execute arbitrary code in the context of the cached document by creating an element with a malicious href attribute and clicking it.
Mitigation:
Upgrade to the latest version of Safari.