Cross-Domain Vulnerability in Apple WebCore on Mac OS X
CVE-2007-2409

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
3 August 2007

What is CVE-2007-2409?

A cross-domain vulnerability exists in the WebCore component of Apple’s Mac OS X versions 10.3.9 and 10.4.10. This flaw allows remote attackers to gather sensitive information by exploiting popup windows that can access the current URL of the parent window. If successfully exploited, this vulnerability exposes users to potential privacy breaches, making it critical to ensure proper safeguards are in place to mitigate unauthorized data access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.