Vulnerability Description
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | < 16.10.0.2357 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96517Third Party AdvisoryVDB Entry
- https://yandex.com/blog/security-changelogs/fixed-in-version-16-10Vendor Advisory
- http://www.securityfocus.com/bid/96517Third Party AdvisoryVDB Entry
- https://yandex.com/blog/security-changelogs/fixed-in-version-16-10Vendor Advisory
FAQ
What is CVE-2016-8507?
CVE-2016-8507 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video a...
How severe is CVE-2016-8507?
CVE-2016-8507 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8507?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser.