← Vulnerability feed

Vulnerability record · CVE-2011-3230 · published 14 October 2011

CVE-2011-3230: Apple Safari file: URL policy bypass allows code execution

Apple · Safari

Apple Safari before 5.1.1 on Mac OS X fails to enforce an intended policy for file: URLs. A crafted website can abuse this to run arbitrary code on the victim's machine. The flaw is a permissions/access-control weakness in how Safari handles local file references.

6.8 CVSS 2.0 Medium EPSS 49% · top 1.1% CWE-264 · Permissions and access controls
6.8CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base score is 6.8 (MEDIUM) with partial confidentiality, integrity and availability impact, and there is no confirmed exploitation despite a high EPSS score.

What it is

Apple Safari before 5.1.1 on Mac OS X fails to enforce an intended policy for file: URLs. A crafted website can abuse this to run arbitrary code on the victim's machine. The flaw is a permissions/access-control weakness in how Safari handles local file references.

Impact

An attacker who lures a user to a malicious site can execute arbitrary code with the privileges of the Safari process, potentially leading to full compromise of the user's account and data.

Attack surface

Reached over the network via a crafted web site viewed in Safari; no authentication is required, but the CVSS vector (AV:N/AC:M/Au:N) indicates some user interaction or a non-trivial condition is needed to trigger it.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tag appears in the references; EPSS is high (0.493, 98.8th percentile), suggesting elevated predicted likelihood, but the record provides no confirmed in-the-wild activity.

What to do

  • Upgrade Safari to 5.1.1 or later on affected Mac OS X systems (Apple advisory HT5000).
  • If immediate upgrade is not possible, restrict browsing to trusted sites and avoid untrusted links that may invoke file: URL handling.
  • Enforce browser hardening and disable or restrict local file access where policy allows.
  • Monitor vendor advisories for any backported fixes on supported OS versions.

Detection

  • Review Safari version inventory to identify hosts still running versions before 5.1.1.
  • Monitor endpoint logs for Safari spawning unexpected child processes or accessing unusual file: paths.
  • Watch for suspicious outbound browsing patterns or downloads preceding local file execution on macOS endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-3230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed8.8CVE-2025-43529Apple WebKit use-after-free allows code execution via crafted web contentA use-after-free flaw in Apple's WebKit engine was fixed through improved memory management across Safari, iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 8.8%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed8.8CVE-2023-43000Apple WebKit use-after-free via malicious web contentA use-after-free flaw in Apple's WebKit engine was fixed by improved memory management in macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, and iOS/i…KEVEPSS 3.9%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2025-6558Chrome ANGLE and GPU input validation flaw enables sandbox escapeGoogle Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigge…KEVEPSS 9.6%analysed8.8CVE-2024-44308Apple WebKit code execution via malicious web contentApple fixed a WebKit flaw with improved checks across Safari, iOS, iPadOS, macOS and visionOS. Processing maliciously crafted web content can lead to…KEVEPSS 10%analysed8.8CVE-2024-23222Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was addressed with improved checks. Processing maliciously crafted web content can lead to arbitrary c…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2011-3230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.