CVE-2016-4585 is a cross-site scripting vulnerability in the WebKit Page Loading implementation affecting Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2. The flaw is triggered when Safari mishandles an HTTP redirection response containing a crafted redirect target. Available technical detail indicates the bug is tied to insufficient validation of redirect URLs, particularly malformed host and port handling during redirection. In vulnerable versions, Safari could accept an invalid non-numeric port in a redirect target, connect using the default port, and propagate a malformed host value, creating conditions for host header manipulation and origin confusion. These behaviors could be leveraged to inject arbitrary web script or HTML, bypass normal origin expectations, and cause cross-origin data exfiltration or spoofed content rendering in Safari. Apple addressed the issue by improving URL validation during redirection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-site scripting vulnerability in WebKit Page Loading affecting Apple iOS, Safari, and tvOS, allowing remote attackers to inject arbitrary web script or HTML through mishandled HTTP redirection responses.
A WebKit Page Loading cross-site scripting issue in Safari URL redirection that may allow cross-origin data exfiltration.
A WebKit Page Loading cross-origin data exfiltration issue caused by cross-site scripting in Safari URL redirection.
A WebKit Page Loading cross-site scripting issue in Safari URL redirection that could enable cross-origin data exfiltration.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.