The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.apple.com/HT204658 | vendor advisory |
http://lists.apple.com/archives/security-announce/2015/Apr/msg00000.html | vendor advisory |
http://www.securitytracker.com/id/1032047 | vdb entry |
http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html | vendor advisory |
http://www.ubuntu.com/usn/USN-2937-1 | vendor advisory |