CVE-2016-1772Sensitive Information Exposure in Apple Safari

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 46.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 17

Description

The Top Sites feature in Apple Safari before 9.1 mishandles cookie storage, which makes it easier for remote web servers to track users via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDapple/safari9.0.3
Appleapple/safari9.1

🔴Vulnerability Details

1
GHSA
GHSA-w7cq-6hf5-43rh: The Top Sites feature in Apple Safari before 92022-05-17

📋Vendor Advisories

1
Apple
CVE-2016-1772: Safari 9.1