The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1033274 | vdb entry third party advisory |
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html | mailing list third party advisory vendor advisory |
http://www.securityfocus.com/bid/76339 | vdb entry third party advisory |
http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html | mailing list vendor advisory |
https://support.apple.com/kb/HT205033 | vendor advisory |