CVE-2010-1386

CRITICAL

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka ...

Affects 1 product across 1 vendor.

BCS7.61
CVSS 2.010.0
EPSS2.1%
Percentile80th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2010. A critical vulnerability affects Apple systems (CVE-2010-1386). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2010-GLOBAL-322137-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2010-1386?
This vulnerability was disclosed in 2010. A critical vulnerability affects Apple systems (CVE-2010-1386). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2010-1386?
CVE-2010-1386 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.1%.
Is CVE-2010-1386 actively exploited?
No confirmed active exploitation of CVE-2010-1386 as of 2026-05-30.
How do I remediate CVE-2010-1386?
Priority: MEDIUM. Advisory: http://secunia.com/advisories/41856 PSIRT: [email protected]
What systems are affected by CVE-2010-1386?
CVE-2010-1386 affects: Apple.
Vulnerability Details
CVE IDCVE-2010-1386
BSIDBS-2010-GLOBAL-322137-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2010-08-19
Last Modified2026-04-29
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Apple Webkit
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5828 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashc1a6a7a437420a867f28e8dbe8b43aea15da3aba7bb55f12f01ad64229bdd3b46b716071e536355e7640015e33d5b4310430262e5a37eb101ed2c69d2eb4ede2
Related CVEs affecting Apple
CVE-2007-2387 10.0 Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardwa... CVE-2014-0590 10.0 Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on W... CVE-2014-4488 10.0 IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple T... CVE-2018-4091 10.0 An issue was discovered in certain Apple products. macOS before 10.13.3 is af... CVE-2003-0426 10.0 The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f s...
View all Apple CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →