The host is installed with Apple Mac OS X or Server 10.11.x before 10.11.2 and is prone to a security bypass vulnerability. A flaw is present in the application, which fails to properly handle a crafted URL. Successful exploitation could allow remote attackers to bypass the HSTS protection mechanism.