First published: Tue Sep 19 2017(Updated: )
WebKit Storage. An information leakage issue existed in the handling of website data in Safari Private windows. This issue was addressed with improved data handling.
Credit: Rich Shawn O’Connell an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <=10.1.2 | |
Apple iOS | <11 | 11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7142 is a vulnerability in Safari before version 11 that allows attackers to bypass the Safari Private Browsing protection mechanism and obtain sensitive information about visited websites.
Safari before version 11 and Apple iOS before version 11 are affected by CVE-2017-7142.
The severity of CVE-2017-7142 is medium with a CVSS score of 5.3.
To fix CVE-2017-7142, it is recommended to update Safari to version 11 or later and Apple iOS to version 11 or later.
You can find more information about CVE-2017-7142 on the following references: [SecurityFocus](http://www.securityfocus.com/bid/100996), [SecurityTracker](http://www.securitytracker.com/id/1039384), [Apple Support](https://support.apple.com/HT208116).