CVE-2016-4604: Apple Safari

Medium severity, CVSS 5.4. EPSS: 1.2% chance of exploitation in the next 30 days.

Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.

Affected products

  • Apple Safari: any version

Published 2016-07-22. Last modified 2026-06-17.