loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation24 reference(s) from NVD