cbcvebase.
CVE-2017-7144
published 2017-10-23

CVE-2017-7144: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It…

PriorityP418medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
0.45%
63.8th percentile
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.

Affected

4 ranges
VendorProductVersion rangeFixed in
appleios
appleiphone_os<= 10.3.3
applesafari<= 10.1.2
applesafari

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N