CVE-2014-1297: Apple Safari
Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
Affected products
- Apple Safari: up to and including 6.1.2; version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; …
Published 2014-04-02. Last modified 2026-06-17.