CVE-2012-3693: Apple Safari
Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.
Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of IDN support and Unicode fonts to construct unspecified homoglyphs.
Affected products
- Apple Safari: up to and including 5.1.7; version 1.0 only; version 1.0.0 only; version 1.0.0b1 only; version 1.0.0b2 only; version 1.0.1 only; …
Published 2012-07-25. Last modified 2026-06-16.