CVE-2015-3754Sensitive Information Exposure in Apple Safari

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 33.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 14

Description

The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-vcw5-5m6w-mgw3: The private-browsing implementation in WebKit in Apple Safari before 62022-05-14
OSV
CVE-2015-3754: The private-browsing implementation in WebKit in Apple Safari before 62015-08-16

📋Vendor Advisories

1
Apple
CVE-2015-3754: Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8
CVE-2015-3754 — Sensitive Information Exposure in Apple | cvebase