WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Itunes | Apple | * | 12.4.3 (including) |
| Qtwebkit-opensource-src | Ubuntu | devel | * |
| Qtwebkit-opensource-src | Ubuntu | esm-infra/xenial | * |
| Qtwebkit-opensource-src | Ubuntu | trusty | * |
| Qtwebkit-opensource-src | Ubuntu | xenial | * |
| Qtwebkit-opensource-src | Ubuntu | yakkety | * |
| Qtwebkit-source | Ubuntu | devel | * |
| Qtwebkit-source | Ubuntu | esm-apps/xenial | * |
| Qtwebkit-source | Ubuntu | precise | * |
| Qtwebkit-source | Ubuntu | trusty | * |
| Qtwebkit-source | Ubuntu | xenial | * |
| Qtwebkit-source | Ubuntu | yakkety | * |
| Webkit | Ubuntu | precise | * |
| Webkit2gtk | Ubuntu | upstream | * |
| Webkitgtk | Ubuntu | devel | * |
| Webkitgtk | Ubuntu | esm-apps/xenial | * |
| Webkitgtk | Ubuntu | trusty | * |
| Webkitgtk | Ubuntu | xenial | * |
| Webkitgtk | Ubuntu | yakkety | * |