vendor:
iOS
by:
Google Project Zero Team
8.8
CVSS
HIGH
Type Confusion
843
CWE
Product Name: iOS
Affected Version From: WebKit before r206375
Affected Version To: WebKit before r206375
Patch Exists: YES
Related CWE: CVE-2016-1841
CPE: a:apple:webkit
Platforms Tested:
2016
Type Confusion in JavascriptArray::ConcatArgs Method
The JavascriptArray::ConcatArgs method in JavaScriptCore in WebKit before r206375, as used in Apple iOS before 9.3.2, mishandles the spread operator, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site.
Mitigation:
Apply the appropriate update provided by the vendor to address this vulnerability.