CVE-2007-4698: Apple Safari

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.

Affected products

  • Apple Safari: up to and including 3.0.3

Published 2007-11-15. Last modified 2026-06-16.