CVE-2016-7153: Infoleak
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7153?
CVE-2016-7153 has been assigned a medium severity rating due to its potential to leak sensitive information.
How do I fix CVE-2016-7153?
To fix CVE-2016-7153, ensure that your web browser is updated to the latest version provided by the browser vendor.
Which browsers are affected by CVE-2016-7153?
CVE-2016-7153 affects multiple browsers, including Microsoft Edge, Internet Explorer, Google Chrome, Apple Mobile Safari, Opera, and Mozilla Firefox.
What type of attack is associated with CVE-2016-7153?
CVE-2016-7153 is associated with a HEIST attack, which allows attackers to exploit improperly handled data in HTTP/2.
Can CVE-2016-7153 lead to data exposure?
Yes, CVE-2016-7153 can lead to the exposure of sensitive data such as user credentials if exploited.