CVE-2013-0982: Infoleak
The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0982?
CVE-2013-0982 is considered a medium severity vulnerability due to potential cookie-based authentication bypass.
How do I fix CVE-2013-0982?
To fix CVE-2013-0982, you should update your macOS to at least version 10.8.4 or later.
What systems are affected by CVE-2013-0982?
CVE-2013-0982 affects Apple Mac OS X versions from 10.7.0 to 10.8.3.
What kind of attacks can CVE-2013-0982 facilitate?
CVE-2013-0982 may allow physical attackers to gain unauthorized access by exploiting leftover permanent cookies.
Is there a workaround for CVE-2013-0982?
There is no specific workaround for CVE-2013-0982; users should upgrade to a patched version to mitigate the risk.