First published: Sun Aug 16 2015(Updated: )
The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | >=6.0<6.2.8 | |
Apple Mobile Safari | >=7.0<7.1.8 | |
Apple Mobile Safari | >=8.0<8.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3754 has a medium severity rating due to its potential to expose private user data.
To fix CVE-2015-3754, users should update their Safari browser to versions 6.2.8, 7.1.8, or 8.0.8 or later.
CVE-2015-3754 allows attackers to track users by potentially accessing cached HTTP authentication credentials.
CVE-2015-3754 affects Apple Safari versions prior to 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8.
Yes, CVE-2015-3754 specifically affects the private browsing implementation in Safari.