CVE-2016-1781: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles attachment URLs, which makes it easier for remote web servers to track users via unspecified vectors.

Affected products

  • Apple iPhone OS: up to and including 9.2.1
  • Apple Safari: up to and including 9.0.3

Published 2016-03-24. Last modified 2026-06-17.