Title: Apple Mac OS X CoreTypes Crafted Archive JavaScript Same-origin Policy Bypass
Info
Disclosure
Mar 10, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Mac OS X CoreTypes contains a flaw that may allow a malicious webpage access to the properties of another domain. The issue is triggered due to the application's failure to properly enforce same-origin policy for JavaScript remote data access. It is possible that the flaw may allow disclosure of sensitive information or may facilitate other attacks against a user of the browser, resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Other
Impact:
Loss of Confidentiality
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch to address this vulnerability.