CVE Published: 01/03/2017 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: yandex |
Vendor: Yandex N.V. |
Product: Yandex Browser for iOS Status : PUBLISHED
CVE-2016-8507 Description
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user\'s approval and obtain video and audio data from a device via a crafted web site.