First published: Tue Sep 19 2017(Updated: )
WebKit. A permissions issue existed in the handling of web browser cookies. This issue was addressed with improved restrictions.
Credit: Mohammad Ghasemisharif UIC product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <=10.1.2 | |
Apple iPhone OS | <=10.3.3 | |
Apple iOS | <11 | 11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-7144.
iOS before version 11 and Safari before version 11 are affected by this vulnerability.
The severity of CVE-2017-7144 is medium with a severity value of 4.3.
Remote attackers can exploit this vulnerability by leveraging cookie mishandling to track Safari Private Browsing users.
Yes, you can find references for CVE-2017-7144 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/100991), [SecurityTracker](http://www.securitytracker.com/id/1039384), [SecurityTracker](http://www.securitytracker.com/id/1039427).