Apple patched CVE-2016-4585, a WebKit page-loading vulnerability in Safari that allowed remote attackers to inject arbitrary script or HTML through specially crafted HTTP redirections. The flaw affected Safari before 9.1.2, iOS before 9.3.3, and tvOS before 9.2.2, and stemmed from improper handling of redirect targets with malformed, non-numeric ports. Researchers showed Safari could send invalid Host headers after following such redirects, creating exploitable conditions in web applications that reflected the header into pages, scripts, links, forms, anchors, or subsequent Location values.
The research also described an origin confusion condition in which pages reached through the malformed redirect could execute in a broken security context. When combined with an iframe, relative resources from a target page could be resolved against an attacker-controlled site, enabling cross-site scripting, spoofing, information theft, and possible content exfiltration or alteration under specific application conditions. Apple addressed the issue by tightening redirect URL validation so invalid redirection URLs trigger an error instead of being processed.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2016-4585 was updated. The record notes the update date and retains references to Apple advisories and related third-party material.
A public research write-up detailed how malformed redirect URLs could cause Safari to send invalid Host headers and create a broken-origin condition, enabling XSS or information theft under certain application conditions. The disclosure also documented iframe-based exploitation and Apple's validation-based fix behavior.
The CVE record for CVE-2016-4585 was published, describing a WebKit Page Loading cross-site scripting vulnerability in Safari, iOS, and tvOS triggered by mishandled HTTP redirections. The entry identified Apple as the CNA and linked Apple advisories and third-party references.
Apple fixed the vulnerability by strengthening validation of redirect URLs so invalid redirect targets produce an error page. The affected products were Safari before 9.1.2, iOS before 9.3.3, and tvOS before 9.2.2, and users were advised to upgrade to versions released on or after July 18, 2016.
The Safari URL handling vulnerability later assigned CVE-2016-4585 was reported to Apple and Japan's IPA in September 2015. The flaw involved crafted redirect URLs that could enable Host header manipulation and origin-confusion-based XSS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.