CVE-2015-5860
18.09.2015, 11:00
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.Enginsight
Vendor | Product | Version |
---|---|---|
apple | iphone_os | 𝑥 ≤ 8.4.1 |
apple | watchos | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References