CVE

Id
81030  
CVE No.
CVE-2015-3753  
Status
Candidate  
Description
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.  
Phase
Assigned (20150507)  
Votes
None (candidate not yet proposed)  
Comments